GMER 1.0.15.15640 -
http://www.gmer.netRootkit scan 2011-07-13 07:16:27
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 ST9100827AS rev.3.BHD
Running: gmer.exe; Driver: C:\Users\karoni\AppData\Local\Temp\axdiipog.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8747DD48]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8747DD72]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8747DD5E]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8747DD34]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 8302E5C5 5 Bytes JMP 8747DD38 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text ntkrnlpa.exe!ZwSaveKey + 13C1 83040339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83079D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\services.exe[552] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00380FEF
.text C:\Windows\system32\services.exe[552] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00380FCD
.text C:\Windows\system32\services.exe[552] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00380FDE
.text C:\Windows\system32\services.exe[552] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 004C0F5E
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 004C0F06
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 004C0F17
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 004C0025
.text C:\Windows\system32\services.exe[552] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 004C0F8A
.text C:\Windows\system32\services.exe[552] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 004C0062
.text C:\Windows\system32\services.exe[552] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 004C0051
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 004C0FE5
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 004C0000
.text C:\Windows\system32\services.exe[552] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 004C00AC
.text C:\Windows\system32\services.exe[552] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 004C0F43
.text C:\Windows\system32\services.exe[552] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 004C0FAF
.text C:\Windows\system32\services.exe[552] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 004C0036
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 004C0F6F
.text C:\Windows\system32\services.exe[552] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 004C0FCA
.text C:\Windows\system32\services.exe[552] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 004C0F32
.text C:\Windows\system32\services.exe[552] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 004C0073
.text C:\Windows\system32\services.exe[552] msvcrt.dll!_open 764B7E48 5 Bytes JMP 004B0FEF
.text C:\Windows\system32\services.exe[552] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 004B0062
.text C:\Windows\system32\services.exe[552] msvcrt.dll!system 764EB16F 5 Bytes JMP 004B0FCD
.text C:\Windows\system32\services.exe[552] msvcrt.dll!_creat 764EED29 5 Bytes JMP 004B0018
.text C:\Windows\system32\services.exe[552] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 004B003D
.text C:\Windows\system32\services.exe[552] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 004B0FDE
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 004D0FE5
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 004D0039
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 004D0FB2
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 004D004A
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 004D0FD4
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 004D006F
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 004D0FC3
.text C:\Windows\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 004D0014
.text C:\Windows\system32\services.exe[552] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00520000
.text C:\Windows\system32\lsass.exe[564] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 001A0FE5
.text C:\Windows\system32\lsass.exe[564] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 001A0FCA
.text C:\Windows\system32\lsass.exe[564] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 001A000A
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 001C0054
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 001C008A
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 001C0EFF
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 001C0F9E
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 001C0F4D
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 001C0025
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 001C0F68
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 001C0FD4
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 001C0FEF
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 001C009B
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 001C0065
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 001C0000
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 001C0F83
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 001C0F21
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 001C0FB9
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 001C0F10
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 001C0F32
.text C:\Windows\system32\lsass.exe[564] msvcrt.dll!_open 764B7E48 5 Bytes JMP 001B0000
.text C:\Windows\system32\lsass.exe[564] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 001B0FCD
.text C:\Windows\system32\lsass.exe[564] msvcrt.dll!system 764EB16F 5 Bytes JMP 001B0058
.text C:\Windows\system32\lsass.exe[564] msvcrt.dll!_creat 764EED29 5 Bytes JMP 001B002C
.text C:\Windows\system32\lsass.exe[564] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 001B0047
.text C:\Windows\system32\lsass.exe[564] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 001B0011
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 001D0000
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 001D0FC0
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 001D0047
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 001D0FA5
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 001D001B
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 001D0F8A
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 001D0FDB
.text C:\Windows\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 001D002C
.text C:\Windows\system32\lsass.exe[564] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00620000
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 004D000A
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 004D0FEF
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 004D0025
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 0091007D
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 009100C4
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00910F2F
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 0091001B
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00910F80
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00910F91
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00910058
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00910FD4
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00910FE5
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00910F14
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 0091008E
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 0091002C
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00910047
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00910F4A
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 0091000A
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 0091009F
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00910F6F
.text C:\Windows\system32\svchost.exe[692] msvcrt.dll!_open 764B7E48 5 Bytes JMP 004E0000
.text C:\Windows\system32\svchost.exe[692] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 004E0FA8
.text C:\Windows\system32\svchost.exe[692] msvcrt.dll!system 764EB16F 5 Bytes JMP 004E0033
.text C:\Windows\system32\svchost.exe[692] msvcrt.dll!_creat 764EED29 5 Bytes JMP 004E0FD4
.text C:\Windows\system32\svchost.exe[692] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 004E0FC3
.text C:\Windows\system32\svchost.exe[692] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 004E0FEF
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00920000
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00920040
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00920062
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00920051
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 0092001B
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00920F9B
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00920FDE
.text C:\Windows\system32\svchost.exe[692] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 00920FEF
.text C:\Windows\system32\svchost.exe[692] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00970000
.text C:\Windows\system32\svchost.exe[756] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 0019000A
.text C:\Windows\system32\svchost.exe[756] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00190FE5
.text C:\Windows\system32\svchost.exe[756] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 0019001B
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!GetStartupInfoA 76971E10 3 Bytes JMP 0023008E
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!GetStartupInfoA + 4 76971E14 1 Byte [89]
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateProcessW 7697204D 3 Bytes JMP 00230F25
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateProcessW + 4 76972051 1 Byte [89]
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateProcessA 76972082 3 Bytes JMP 002300BA
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateProcessA + 4 76972086 1 Byte [89]
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00230FAF
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00230062
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00230051
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00230F8A
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00230000
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00230FE5
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 002300D5
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00230F40
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 0023001B
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00230036
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 0023007D
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00230FCA
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 0023009F
.text C:\Windows\system32\svchost.exe[756] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00230F6F
.text C:\Windows\system32\svchost.exe[756] msvcrt.dll!_open 764B7E48 5 Bytes JMP 001A000C
.text C:\Windows\system32\svchost.exe[756] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 001A0FC8
.text C:\Windows\system32\svchost.exe[756] msvcrt.dll!system 764EB16F 5 Bytes JMP 001A0053
.text C:\Windows\system32\svchost.exe[756] msvcrt.dll!_creat 764EED29 5 Bytes JMP 001A0038
.text C:\Windows\system32\svchost.exe[756] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 001A0FE3
.text C:\Windows\system32\svchost.exe[756] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 001A001D
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00400000
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00400036
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 0040005B
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00400FB9
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00400FE5
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 0040006C
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00400025
.text C:\Windows\system32\svchost.exe[756] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 00400FD4
.text C:\Windows\system32\svchost.exe[756] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00410FEF
.text C:\Windows\System32\svchost.exe[804] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00770FE5
.text C:\Windows\System32\svchost.exe[804] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00770014
.text C:\Windows\System32\svchost.exe[804] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00770FD4
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00C80F65
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00C800D5
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00C800BA
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00C80FC0
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00C80073
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00C80062
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00C80FAF
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00C80FE5
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00C80000
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00C800F0
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00C80F54
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00C8002C
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00C80047
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00C80F8A
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00C80011
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00C800A9
.text C:\Windows\System32\svchost.exe[804] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00C80098
.text C:\Windows\System32\svchost.exe[804] msvcrt.dll!_open 764B7E48 5 Bytes JMP 00C30000
.text C:\Windows\System32\svchost.exe[804] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00C30033
.text C:\Windows\System32\svchost.exe[804] msvcrt.dll!system 764EB16F 5 Bytes JMP 00C30022
.text C:\Windows\System32\svchost.exe[804] msvcrt.dll!_creat 764EED29 5 Bytes JMP 00C30FD7
.text C:\Windows\System32\svchost.exe[804] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 00C30FBC
.text C:\Windows\System32\svchost.exe[804] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 00C30011
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00CD0000
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00CD004A
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00CD005B
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00CD0FB9
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00CD0FE5
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00CD0FA8
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00CD0FD4
.text C:\Windows\System32\svchost.exe[804] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 00CD0025
.text C:\Windows\System32\svchost.exe[804] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00D20000
.text C:\Windows\System32\svchost.exe[936] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00610000
.text C:\Windows\System32\svchost.exe[936] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00610FD1
.text C:\Windows\System32\svchost.exe[936] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00610011
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00600F46
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00600EEB
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00600EFC
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00600FD4
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00600F97
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00600065
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00600054
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00600FE5
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00600000
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 0060009B
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00600F21
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00600FC3
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00600FB2
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00600F61
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00600025
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00600080
.text C:\Windows\System32\svchost.exe[936] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00600F72
.text C:\Windows\System32\svchost.exe[936] msvcrt.dll!_open 764B7E48 5 Bytes JMP 00660FEF
.text C:\Windows\System32\svchost.exe[936] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00660038
.text C:\Windows\System32\svchost.exe[936] msvcrt.dll!system 764EB16F 5 Bytes JMP 00660027
.text C:\Windows\System32\svchost.exe[936] msvcrt.dll!_creat 764EED29 5 Bytes JMP 00660FD2
.text C:\Windows\System32\svchost.exe[936] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 00660FB7
.text C:\Windows\System32\svchost.exe[936] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 0066000C
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 006F0FEF
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 006F0FB9
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 006F005B
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 006F0040
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 006F000A
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 006F0F9E
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 006F002F
.text C:\Windows\System32\svchost.exe[936] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 006F0FD4
.text C:\Windows\System32\svchost.exe[936] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00700000
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00710000
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00710025
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00710FE5
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00700F5E
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00700F17
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 007000B6
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00700FC0
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00700F8A
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00700062
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00700FA5
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00700FDB
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00700000
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00700F06
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00700F4D
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00700036
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00700047
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 0070007D
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00700011
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00700F32
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00700F79
.text C:\Windows\system32\svchost.exe[964] msvcrt.dll!_open 764B7E48 5 Bytes JMP 007A000C
.text C:\Windows\system32\svchost.exe[964] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 007A0042
.text C:\Windows\system32\svchost.exe[964] msvcrt.dll!system 764EB16F 5 Bytes JMP 007A0FB7
.text C:\Windows\system32\svchost.exe[964] msvcrt.dll!_creat 764EED29 5 Bytes JMP 007A0FE3
.text C:\Windows\system32\svchost.exe[964] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 007A0FC8
.text C:\Windows\system32\svchost.exe[964] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 007A001D
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 007B0FE5
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 007B0022
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 007B0F9B
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 007B0033
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 007B0000
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 007B0F80
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 007B0FB6
.text C:\Windows\system32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 007B0011
.text C:\Windows\system32\svchost.exe[964] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00AD0FE5
.text C:\Windows\system32\svchost.exe[1080] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00510000
.text C:\Windows\system32\svchost.exe[1080] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00510036
.text C:\Windows\system32\svchost.exe[1080] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 0051001B
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00500F2F
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00500F0A
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 0050009F
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00500025
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00500F6F
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00500F80
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00500F9B
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00500FE5
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00500000
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00500EEF
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00500073
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00500036
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00500047
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00500F54
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00500FCA
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00500084
.text C:\Windows\system32\svchost.exe[1080] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00500062
.text C:\Windows\system32\svchost.exe[1080] msvcrt.dll!_open 764B7E48 5 Bytes JMP 00560FEF
.text C:\Windows\system32\svchost.exe[1080] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00560058
.text C:\Windows\system32\svchost.exe[1080] msvcrt.dll!system 764EB16F 5 Bytes JMP 00560FCD
.text C:\Windows\system32\svchost.exe[1080] msvcrt.dll!_creat 764EED29 5 Bytes JMP 00560FDE
.text C:\Windows\system32\svchost.exe[1080] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 00560033
.text C:\Windows\system32\svchost.exe[1080] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 00560018
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00570FEF
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00570FAF
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00570047
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00570036
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00570FD4
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00570062
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 0057001B
.text C:\Windows\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 0057000A
.text C:\Windows\system32\svchost.exe[1080] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00610FEF
.text C:\Windows\system32\svchost.exe[1240] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 005C0000
.text C:\Windows\system32\svchost.exe[1240] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 005C0FCA
.text C:\Windows\system32\svchost.exe[1240] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 005C0FE5
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00530F72
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 005300F6
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 005300D1
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00530FCA
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00530F9E
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00530FAF
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00530062
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00530FDB
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00530000
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00530107
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00530F61
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00530036
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00530051
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 0053009B
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 0053001B
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 005300C0
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00530F8D
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_open 764B7E48 5 Bytes JMP 005D0000
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 005D004E
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!system 764EB16F 5 Bytes JMP 005D0FCD
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_creat 764EED29 5 Bytes JMP 005D0022
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 005D003D
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 005D0011
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 005E0000
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 005E0FCA
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 005E0051
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 005E0FB9
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 005E0FE5
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 005E006C
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 005E002C
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 005E001B
.text C:\Windows\system32\svchost.exe[1240] WS2_32.dll!socket 77093EB8 5 Bytes JMP 006C0FEF
.text C:\Windows\system32\svchost.exe[1436] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00DC0FEF
.text C:\Windows\system32\svchost.exe[1436] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00DC0FCD
.text C:\Windows\system32\svchost.exe[1436] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00DC0FDE
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00DB0F5E
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00DB00BA
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00DB00A9
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00DB0025
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00DB0062
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00DB0051
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00DB0F9E
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00DB000A
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00DB0FEF
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00DB00D5
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00DB0098
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00DB0FAF
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00DB0036
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00DB0087
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00DB0FCA
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00DB0F2F
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00DB0F79
.text C:\Windows\system32\svchost.exe[1436] msvcrt.dll!_open 764B7E48 5 Bytes JMP 00E6000C
.text C:\Windows\system32\svchost.exe[1436] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00E60F81
.text C:\Windows\system32\svchost.exe[1436] msvcrt.dll!system 764EB16F 5 Bytes JMP 00E60F9C
.text C:\Windows\system32\svchost.exe[1436] msvcrt.dll!_creat 764EED29 5 Bytes JMP 00E60FC8
.text C:\Windows\system32\svchost.exe[1436] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 00E60FAD
.text C:\Windows\system32\svchost.exe[1436] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 00E60FE3
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00E70FEF
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00E70FAF
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00E70F94
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00E70036
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00E70FDE
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00E70F6F
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00E70025
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 00E70014
.text C:\Windows\system32\svchost.exe[1436] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00F90FEF
.text C:\Windows\System32\svchost.exe[1512] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 003A0FEF
.text C:\Windows\System32\svchost.exe[1512] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 003A000A
.text C:\Windows\System32\svchost.exe[1512] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 003A0FDE
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 003900AC
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 003900FD
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 003900EC
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00390FCA
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 0039006C
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00390051
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00390F94
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00390011
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00390000
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 0039010E
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 003900C7
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00390FAF
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00390036
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00390087
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00390FDB
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00390F68
.text C:\Windows\System32\svchost.exe[1512] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00390F83
.text C:\Windows\System32\svchost.exe[1512] msvcrt.dll!_open 764B7E48 5 Bytes JMP 00400FE3
.text C:\Windows\System32\svchost.exe[1512] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00400000
.text C:\Windows\System32\svchost.exe[1512] msvcrt.dll!system 764EB16F 5 Bytes JMP 00400F75
.text C:\Windows\System32\svchost.exe[1512] msvcrt.dll!_creat 764EED29 5 Bytes JMP 00400FB5
.text C:\Windows\System32\svchost.exe[1512] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 00400F9A
.text C:\Windows\System32\svchost.exe[1512] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 00400FD2
.text C:\Windows\System32\svchost.exe[1512] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00430FEF
.text C:\Windows\System32\svchost.exe[1512] WININET.dll!InternetOpenA 766A4E2B 5 Bytes JMP 00410000
.text C:\Windows\System32\svchost.exe[1512] WININET.dll!InternetOpenUrlA 766ABFCE 5 Bytes JMP 00410FD4
.text C:\Windows\System32\svchost.exe[1512] WININET.dll!InternetOpenW 766DC03E 5 Bytes JMP 00410FE5
.text C:\Windows\System32\svchost.exe[1512] WININET.dll!InternetOpenUrlW 7670D722 5 Bytes JMP 00410FC3
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00420FEF
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00420F97
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00420025
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00420014
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00420FD4
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00420040
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00420FA8
.text C:\Windows\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 00420FC3
.text C:\Windows\Explorer.EXE[1692] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 006D0FE5
.text C:\Windows\Explorer.EXE[1692] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 006D0011
.text C:\Windows\Explorer.EXE[1692] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 006D0000
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 015E0F6F
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 015E0F2F
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 015E00BA
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 015E0FCA
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 015E0F8A
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 015E0FA5
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 015E0062
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 015E0FEF
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 015E0000
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 015E0F0A
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 015E0F4A
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 015E0036
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 015E0047
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 015E0098
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 015E0025
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 015E00A9
.text C:\Windows\Explorer.EXE[1692] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 015E007D
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 015F0000
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 015F0FB9
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 015F0F9E
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 015F004A
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 015F0FE5
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 015F0F83
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 015F0FCA
.text C:\Windows\Explorer.EXE[1692] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 015F001B
.text C:\Windows\Explorer.EXE[1692] msvcrt.dll!_open 764B7E48 5 Bytes JMP 015D000C
.text C:\Windows\Explorer.EXE[1692] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 015D003D
.text C:\Windows\Explorer.EXE[1692] msvcrt.dll!system 764EB16F 5 Bytes JMP 015D0FA8
.text C:\Windows\Explorer.EXE[1692] msvcrt.dll!_creat 764EED29 5 Bytes JMP 015D0FDE
.text C:\Windows\Explorer.EXE[1692] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 015D0FCD
.text C:\Windows\Explorer.EXE[1692] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 015D0FEF
.text C:\Windows\Explorer.EXE[1692] WS2_32.dll!socket 77093EB8 5 Bytes JMP 0191000A
.text C:\Windows\Explorer.EXE[1692] WININET.dll!InternetOpenA 766A4E2B 5 Bytes JMP 04DB0000
.text C:\Windows\Explorer.EXE[1692] WININET.dll!InternetOpenUrlA 766ABFCE 5 Bytes JMP 04DB0FDB
.text C:\Windows\Explorer.EXE[1692] WININET.dll!InternetOpenW 766DC03E 5 Bytes JMP 04DB0011
.text C:\Windows\Explorer.EXE[1692] WININET.dll!InternetOpenUrlW 7670D722 5 Bytes JMP 04DB0FCA
.text C:\Windows\system32\svchost.exe[1944] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 001B0FEF
.text C:\Windows\system32\svchost.exe[1944] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 001B0FAF
.text C:\Windows\system32\svchost.exe[1944] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 001B0FCA
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 001A0080
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 001A00C7
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 001A00AC
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 001A002F
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 001A0F8D
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 001A0FA8
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 001A0065
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 001A0FE5
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 001A0000
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 001A00D8
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 001A0F32
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 001A0040
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 001A0FC3
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 001A0F57
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 001A0FD4
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 001A0091
.text C:\Windows\system32\svchost.exe[1944] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 001A0F72
.text C:\Windows\system32\svchost.exe[1944] msvcrt.dll!_open 764B7E48 5 Bytes JMP 001C0000
.text C:\Windows\system32\svchost.exe[1944] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 001C0033
.text C:\Windows\system32\svchost.exe[1944] msvcrt.dll!system 764EB16F 5 Bytes JMP 001C0022
.text C:\Windows\system32\svchost.exe[1944] msvcrt.dll!_creat 764EED29 5 Bytes JMP 001C0FC6
.text C:\Windows\system32\svchost.exe[1944] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 001C0011
.text C:\Windows\system32\svchost.exe[1944] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 001C0FD7
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 001D0028
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 001D0F97
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 001D0039
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 001D0FDE
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 001D0054
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 001D0FBC
.text C:\Windows\system32\svchost.exe[1944] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 001D0FCD
.text C:\Windows\system32\svchost.exe[2636] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00040FE5
.text C:\Windows\system32\svchost.exe[2636] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00040FCA
.text C:\Windows\system32\svchost.exe[2636] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00040000
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00010F79
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 000100EC
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00010F57
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00010FD4
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 0001006C
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 0001005B
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00010FA8
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00010FE5
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00010000
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00010F3C
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00010F68
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00010036
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00010FB9
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00010098
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 0001001B
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 000100D1
.text C:\Windows\system32\svchost.exe[2636] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00010087
.text C:\Windows\system32\svchost.exe[2636] msvcrt.dll!_open 764B7E48 5 Bytes JMP 00070FE3
.text C:\Windows\system32\svchost.exe[2636] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00070FAB
.text C:\Windows\system32\svchost.exe[2636] msvcrt.dll!system 764EB16F 5 Bytes JMP 00070FBC
.text C:\Windows\system32\svchost.exe[2636] msvcrt.dll!_creat 764EED29 5 Bytes JMP 00070011
.text C:\Windows\system32\svchost.exe[2636] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 0007002C
.text C:\Windows\system32\svchost.exe[2636] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 00070000
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00130000
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00130FDE
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00130076
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00130065
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00130025
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00130091
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00130FEF
.text C:\Windows\system32\svchost.exe[2636] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 00130040
.text C:\Windows\system32\svchost.exe[2636] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00410FEF
.text C:\Windows\system32\wuauclt.exe[4016] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00040FEF
.text C:\Windows\system32\wuauclt.exe[4016] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 0004000A
.text C:\Windows\system32\wuauclt.exe[4016] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00040FD4
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 0001009F
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 000100E6
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00010F51
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00010FAF
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00010073
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00010058
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00010047
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00010FE5
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00010000
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 000100F7
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 000100B0
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00010025
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00010036
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00010F76
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00010FCA
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 000100CB
.text C:\Windows\system32\wuauclt.exe[4016] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00010084
.text C:\Windows\system32\wuauclt.exe[4016] msvcrt.dll!_open 764B7E48 5 Bytes JMP 000F0000
.text C:\Windows\system32\wuauclt.exe[4016] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 000F0058
.text C:\Windows\system32\wuauclt.exe[4016] msvcrt.dll!system 764EB16F 5 Bytes JMP 000F0047
.text C:\Windows\system32\wuauclt.exe[4016] msvcrt.dll!_creat 764EED29 5 Bytes JMP 000F002C
.text C:\Windows\system32\wuauclt.exe[4016] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 000F0FD7
.text C:\Windows\system32\wuauclt.exe[4016] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 000F0011
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00100000
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00100040
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00100FA8
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00100FB9
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00100FE5
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 0010005B
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00100FCA
.text C:\Windows\system32\wuauclt.exe[4016] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 0010001B
.text C:\Windows\system32\svchost.exe[4364] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 0004000A
.text C:\Windows\system32\svchost.exe[4364] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00040FDE
.text C:\Windows\system32\svchost.exe[4364] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 00040FEF
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 000100B6
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00010F4D
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 000100E2
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 00010036
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00010087
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 0001006C
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 0001005B
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00010000
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00010FE5
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 000100FD
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00010F72
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00010FCA
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00010FB9
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 00010F8D
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 0001001B
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 000100D1
.text C:\Windows\system32\svchost.exe[4364] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00010F9E
.text C:\Windows\system32\svchost.exe[4364] msvcrt.dll!_open 764B7E48 5 Bytes JMP 000E0FEF
.text C:\Windows\system32\svchost.exe[4364] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 000E0FAF
.text C:\Windows\system32\svchost.exe[4364] msvcrt.dll!system 764EB16F 5 Bytes JMP 000E0044
.text C:\Windows\system32\svchost.exe[4364] msvcrt.dll!_creat 764EED29 5 Bytes JMP 000E0FD4
.text C:\Windows\system32\svchost.exe[4364] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 000E0033
.text C:\Windows\system32\svchost.exe[4364] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 000E000C
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 00130FEF
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 00130051
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 00130FAF
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 00130FC0
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 00130014
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 00130F94
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 00130040
.text C:\Windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 0013002F
.text C:\Windows\system32\svchost.exe[4364] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00140FEF
.text C:\Windows\System32\svchost.exe[5596] ntdll.dll!NtCreateFile 76EE55C8 5 Bytes JMP 00040000
.text C:\Windows\System32\svchost.exe[5596] ntdll.dll!NtCreateProcess 76EE5698 5 Bytes JMP 00040040
.text C:\Windows\System32\svchost.exe[5596] ntdll.dll!NtProtectVirtualMemory 76EE5F18 5 Bytes JMP 0004001B
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!GetStartupInfoA 76971E10 5 Bytes JMP 00010F17
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreateProcessW 7697204D 5 Bytes JMP 00010087
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreateProcessA 76972082 5 Bytes JMP 00010076
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreateNamedPipeW 769A270F 5 Bytes JMP 0001000A
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!VirtualProtect 769B2341 5 Bytes JMP 00010F57
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!LoadLibraryExW 769B4775 5 Bytes JMP 00010F68
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!LoadLibraryExA 769B47FA 5 Bytes JMP 00010025
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreateFileW 769BCC56 5 Bytes JMP 00010FDE
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreateFileA 769BCEE8 5 Bytes JMP 00010FEF
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!GetProcAddress 769C33D3 5 Bytes JMP 00010EE1
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!GetStartupInfoW 769C3891 5 Bytes JMP 00010065
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!LoadLibraryA 769C395C 5 Bytes JMP 00010F94
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!LoadLibraryW 769C3C01 5 Bytes JMP 00010F83
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreatePipe 769D35B7 5 Bytes JMP 0001004A
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!CreateNamedPipeA 769FD44F 5 Bytes JMP 00010FB9
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!WinExec 769FE5FD 5 Bytes JMP 00010F06
.text C:\Windows\System32\svchost.exe[5596] kernel32.dll!VirtualProtectEx 769FF5D9 5 Bytes JMP 00010F3C
.text C:\Windows\System32\svchost.exe[5596] msvcrt.dll!_open 764B7E48 5 Bytes JMP 0022000C
.text C:\Windows\System32\svchost.exe[5596] msvcrt.dll!_wsystem 764EB04F 5 Bytes JMP 00220FC8
.text C:\Windows\System32\svchost.exe[5596] msvcrt.dll!system 764EB16F 5 Bytes JMP 00220053
.text C:\Windows\System32\svchost.exe[5596] msvcrt.dll!_creat 764EED29 5 Bytes JMP 0022002E
.text C:\Windows\System32\svchost.exe[5596] msvcrt.dll!_wcreat 764F038E 5 Bytes JMP 00220FE3
.text C:\Windows\System32\svchost.exe[5596] msvcrt.dll!_wopen 764F0570 5 Bytes JMP 0022001D
.text C:\Windows\System32\svchost.exe[5596] WS2_32.dll!socket 77093EB8 5 Bytes JMP 00230FEF
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegOpenKeyA 76FECC15 5 Bytes JMP 002B0FEF
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegCreateKeyA 76FECD01 5 Bytes JMP 002B0FA5
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegCreateKeyExA 76FF1469 5 Bytes JMP 002B0051
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegCreateKeyW 76FF1514 5 Bytes JMP 002B002C
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegOpenKeyW 76FF2459 5 Bytes JMP 002B0FD4
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegCreateKeyExW 76FF40FE 5 Bytes JMP 002B0F94
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegOpenKeyExW 76FF468D 5 Bytes JMP 002B001B
.text C:\Windows\System32\svchost.exe[5596] ADVAPI32.dll!RegOpenKeyExA 76FF4907 5 Bytes JMP 002B000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\System32\svchost.exe[936] @ C:\Windows\System32\svchost.exe [KERNEL32.dll!ExitProcess] [3052CBB4] C:\Program Files\Spybot - Search & Destroy 2\SDCoffPH.dll (Hooks for on-access monitoring/Safer-Networking Ltd.)
IAT C:\Windows\system32\svchost.exe[964] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!ExitProcess] [3052CBB4] C:\Program Files\Spybot - Search & Destroy 2\SDCoffPH.dll (Hooks for on-access monitoring/Safer-Networking Ltd.)
IAT C:\Windows\system32\mfevtps.exe[1580] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [00D9A510] C:\Windows\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73CD2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73CB5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73CB56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73CD24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73CC8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73CC4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73CC506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73CC5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73CC6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73CC826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73CC87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73CC901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73CCE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1692] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73CC4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2760] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2760] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2760] @ C:\Windows\system32\advapi32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2760] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2760] @ C:\Windows\system32\crypt32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2760] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[6116] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[6116] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[6116] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[6116] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [74F7FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs MOBK.sys (Mozy Change Monitor Filter Driver/Mozy, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000054 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat MOBK.sys (Mozy Change Monitor Filter Driver/Mozy, Inc.)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- EOF - GMER 1.0.15 ----
OTL logfile created on: 7/13/2011 07:32:09 - Run 4
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\karoni\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.62 Mb Total Physical Memory | 42.11 Mb Available Physical Memory | 8.23% Memory free
2.94 Gb Paging File | 1.78 Gb Available in Paging File | 60.39% Paging File free
Paging file location(s): c:\pagefile.sys 2500 2500 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 87.62 Gb Total Space | 65.26 Gb Free Space | 74.48% Space Free | Partition Type: NTFS
Drive D: | 5.54 Gb Total Space | 1.05 Gb Free Space | 18.92% Space Free | Partition Type: NTFS
Drive F: | 29.91 Gb Total Space | 25.91 Gb Free Space | 86.62% Space Free | Partition Type: FAT32
Computer Name: KARONI-PC | User Name: karoni | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/07/05 23:04:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\karoni\Downloads\OTL.exe
PRC - [2011/05/25 21:24:16 | 001,306,216 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/05/11 15:10:44 | 000,167,040 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2011/05/10 22:28:30 | 003,769,048 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2011/05/10 22:21:12 | 003,834,456 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDMonSvc.exe
PRC - [2011/05/10 22:18:34 | 003,585,696 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFWSvc.exe
PRC - [2011/05/10 22:18:08 | 003,515,656 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2011/03/13 11:45:14 | 000,148,520 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2011/03/13 11:41:50 | 000,159,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/03/13 11:41:36 | 000,165,000 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/12/15 23:46:06 | 000,151,056 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\Core\mchost.exe
PRC - [2010/11/20 08:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/20 08:17:00 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2006/10/10 20:44:20 | 000,034,520 | ---- | M] (Hewlett Packard) -- C:\Program Files\Compaq Connections\3572475\Program\Compaq Connections.exe
========== Modules (SafeList) ========== MOD - [2011/07/05 23:04:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\karoni\Downloads\OTL.exe
MOD - [2011/04/08 16:56:28 | 000,018,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/11/20 07:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (0275281310315314mcinstcleanup) McAfee Application Installer Cleanup (0275281310315314)
SRV - [2011/06/29 17:43:25 | 003,435,096 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_e477fed.dll -- (Akamai)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/11 15:10:44 | 000,167,040 | ---- | M] (Safer-Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe -- (SDWSCService)
SRV - [2011/05/10 22:28:30 | 003,769,048 | ---- | M] (Safer-Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe -- (SDUpdateService)
SRV - [2011/05/10 22:21:12 | 003,834,456 | ---- | M] (Safer-Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy 2\SDMonSvc.exe -- (SDMonitorService)
SRV - [2011/05/10 22:18:34 | 003,585,696 | ---- | M] (Safer-Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy 2\SDFWSvc.exe -- (SDFirewallService)
SRV - [2011/05/10 22:18:08 | 003,515,656 | ---- | M] (Safer-Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe -- (SDScannerService)
SRV - [2011/03/17 16:38:42 | 000,361,712 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2011/03/13 11:45:14 | 000,148,520 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/03/13 11:41:50 | 000,159,832 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2011/03/13 11:41:36 | 000,165,000 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2010/10/14 17:27:38 | 000,092,216 | ---- | M] (Hewlett-Packard Company) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
SRV - [2010/04/25 10:57:16 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/04/13 21:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Stopped] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2006/06/26 13:50:08 | 000,126,976 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe -- (AddFiltr)
SRV - [2004/10/22 07:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
========== Driver Services (SafeList) ========== DRV - [2011/03/13 11:20:10 | 000,459,728 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/03/13 11:20:10 | 000,337,912 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/03/13 11:20:10 | 000,179,248 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/03/13 11:20:10 | 000,163,400 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/03/13 11:20:10 | 000,118,784 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/03/13 11:20:10 | 000,085,984 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/03/13 11:20:10 | 000,064,648 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/03/13 11:20:10 | 000,059,288 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/03/13 11:20:10 | 000,057,432 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/04/13 21:10:22 | 000,054,776 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\MOBK.sys -- (MOBKFilter)
DRV - [2010/02/25 00:02:30 | 000,015,544 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2009/11/04 16:54:12 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/11/04 16:53:40 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2008/07/22 07:42:58 | 000,051,200 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/03/04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/07/10 06:27:56 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2006/11/02 10:43:50 | 000,145,920 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2006/06/28 13:57:00 | 000,008,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\eabfiltr.sys -- (eabfiltr)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...SARIO&pf=laptop IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.facebook.com/login
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\karoni\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\karoni\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/23 21:24:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/23 21:24:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/05/24 18:41:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\Google\Web Accelerator\firefox [2011/06/23 18:39:43 | 000,000,000 | ---D | M]
FF - HKCU\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/23 21:24:27 | 000,000,000 | ---D | M]
FF - HKCU\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/23 21:24:28 | 000,000,000 | ---D | M]
FF - HKCU\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/05/24 18:41:36 | 000,000,000 | ---D | M]
FF - HKCU\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\Google\Web Accelerator\firefox [2011/06/23 18:39:43 | 000,000,000 | ---D | M]
[2010/04/24 18:41:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\karoni\AppData\Roaming\Mozilla\Extensions
[2010/04/16 21:33:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\karoni\AppData\Roaming\Mozilla\Extensions\
[email protected] O1 HOSTS File: ([2011/07/11 18:32:52 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - File not found
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (&Google Web Accelerator Helper) - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110616185531.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O15 - HKCU\..Trusted Domains: combofix.exe ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: infospyware.net ([www] http in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper: C:\Users\karoni\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\karoni\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O32 - AutoRun File - [2010/05/05 16:20:58 | 000,000,103 | ---- | M] () - F:\Autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/07/13 05:54:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/07/12 07:57:14 | 000,000,000 | ---D | C] -- C:\Windows\TEMP
[2011/07/12 07:47:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/07/12 07:19:29 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/07/11 17:56:35 | 000,518,144 | R--- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/07/11 17:56:35 | 000,406,528 | R--- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/07/11 17:50:34 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/07/10 23:38:14 | 000,000,000 | ---D | C] -- C:\Users\karoni\AppData\Local\temp
[2011/07/04 12:30:29 | 000,056,400 | ---- | C] (trend_company_name) -- C:\Windows\System32\drivers\tmrkb.sys
[2011/07/04 12:30:28 | 000,190,032 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2011/07/03 12:48:48 | 000,000,000 | ---D | C] -- C:\Users\karoni\FrostWire
[2011/07/03 11:06:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup (Disabled by AnVir)
[2011/07/03 10:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager Free
[2011/07/03 10:39:02 | 000,000,000 | ---D | C] -- C:\Program Files\AnVir Task Manager Free
[2011/07/03 10:38:01 | 000,000,000 | ---D | C] -- C:\Users\karoni\AppData\Local\AnVir
[2011/07/02 13:53:31 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011/07/02 13:53:27 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011/07/02 13:53:24 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2011/07/02 13:51:29 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2011/07/02 13:50:17 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2011/07/02 13:49:56 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2011/07/02 13:49:55 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2011/07/02 13:49:52 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2011/07/02 13:49:47 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2011/07/02 13:49:45 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2011/07/02 13:49:43 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2011/06/28 19:28:12 | 000,000,000 | ---D | C] -- C:\Users\karoni\Desktop\log
[2011/06/24 18:14:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2011/06/24 18:14:13 | 000,015,224 | ---- | C] (Safer Networking Limited) -- C:\Windows\System32\sdnclean.exe
[2011/06/24 18:13:35 | 000,770,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcr100.dll
[2011/06/24 18:13:35 | 000,421,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp100.dll
[2011/06/24 18:08:52 | 000,000,000 | ---D | C] -- C:\Users\karoni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire
[2011/06/23 18:39:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Web Accelerator
[2011/06/23 18:28:00 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2
[2011/06/23 18:23:35 | 000,000,000 | ---D | C] -- C:\Users\karoni\AppData\Roaming\SUPERAntiSpyware.com
[2011/06/23 18:23:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/06/23 18:23:10 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/06/23 18:19:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/06/23 18:19:12 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/06/23 18:19:12 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/06/23 18:19:12 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/06/23 18:18:37 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2011/06/20 20:34:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/06/20 20:34:37 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/06/17 18:07:33 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/06/17 18:07:31 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/06/17 18:07:31 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/06/17 18:07:30 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/06/17 18:05:50 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2010/10/13 19:17:07 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\karoni\AppData\Roaming\pcouffin.sys
[2010/09/03 22:07:39 | 003,063,561 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\MobileTV.exe
[2010/09/03 22:07:39 | 002,989,660 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\DVD.exe
[2010/09/03 22:07:38 | 002,864,396 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\MPV.exe
[2010/09/03 22:07:38 | 002,331,174 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\Karaoke.exe
[2010/09/03 22:07:37 | 002,231,606 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\Games.exe
========== Files - Modified Within 30 Days ========== [2011/07/13 07:23:15 | 000,132,597 | ---- | M] () -- C:\Users\karoni\Desktop\Flash_Disinfector.exe
[2011/07/13 06:44:31 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1643368254-1818270169-1135579119-1000UA.job
[2011/07/13 06:21:10 | 000,009,728 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/13 06:21:10 | 000,009,728 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/13 06:15:06 | 000,293,977 | ---- | M] () -- C:\Users\karoni\Desktop\gmer.zip
[2011/07/13 05:52:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/07/13 05:52:39 | 402,350,080 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/12 18:44:20 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1643368254-1818270169-1135579119-1000Core.job
[2011/07/12 18:00:02 | 000,000,446 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Registration3.job
[2011/07/11 22:51:22 | 162,372,208 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/07/11 22:36:18 | 000,000,606 | ---- | M] () -- C:\Users\karoni\Desktop\fsecuree
[2011/07/11 18:32:52 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/07/05 21:26:00 | 000,001,041 | ---- | M] () -- C:\Users\karoni\AppData\Roaming\vso_ts_preview.xml
[2011/07/04 18:31:34 | 000,000,691 | ---- | M] () -- C:\Users\karoni\AppData\Roaming\GetValue.vbs
[2011/07/04 18:31:34 | 000,000,035 | ---- | M] () -- C:\Users\karoni\AppData\Roaming\SetValue.bat
[2011/07/04 12:30:29 | 000,056,400 | ---- | M] (trend_company_name) -- C:\Windows\System32\drivers\tmrkb.sys
[2011/07/04 12:30:28 | 000,190,032 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2011/07/04 12:05:45 | 000,624,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/07/04 12:05:45 | 000,106,522 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/07/03 10:39:04 | 000,000,997 | ---- | M] () -- C:\Users\karoni\Application Data\Microsoft\Internet Explorer\Quick Launch\AnVir Task Manager Free.lnk
[2011/07/03 10:39:03 | 000,001,039 | ---- | M] () -- C:\Users\Public\Desktop\AnVir Task Manager Free.lnk
[2011/07/02 17:35:22 | 000,389,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/06/30 17:54:24 | 000,012,660 | ---- | M] () -- C:\Users\karoni\Documents\cc_20110630_175401.reg
[2011/06/26 12:34:12 | 000,000,000 | ---- | M] () -- C:\Users\karoni\AppData\Roaming\.googlewebacchosts
[2011/06/26 02:45:56 | 000,256,000 | ---- | M] () -- C:\Windows\PEV.exe
[2011/06/24 18:14:15 | 000,002,123 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2011/06/24 18:08:53 | 000,001,203 | ---- | M] () -- C:\Users\karoni\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.8.lnk
[2011/06/24 18:08:52 | 000,001,179 | ---- | M] () -- C:\Users\karoni\Desktop\FrostWire 4.21.8.lnk
[2011/06/23 18:39:44 | 000,001,181 | ---- | M] () -- C:\Users\karoni\Desktop\Google Web Accelerator.lnk
[2011/06/23 18:23:27 | 000,001,965 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/06/23 18:18:49 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/06/23 18:18:49 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/06/23 18:18:48 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/06/23 18:18:46 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011/06/23 18:16:26 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/20 20:35:20 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
========== Files Created - No Company Name ========== [2011/07/13 07:22:57 | 000,132,597 | ---- | C] () -- C:\Users\karoni\Desktop\Flash_Disinfector.exe
[2011/07/13 06:15:18 | 000,293,977 | ---- | C] () -- C:\Users\karoni\Desktop\gmer.zip
[2011/07/11 22:36:18 | 000,000,606 | ---- | C] () -- C:\Users\karoni\Desktop\fsecuree
[2011/07/11 17:56:39 | 000,208,896 | R--- | C] () -- C:\Windows\MBR.exe
[2011/07/11 17:56:35 | 000,098,816 | R--- | C] () -- C:\Windows\sed.exe
[2011/07/11 17:56:35 | 000,080,412 | R--- | C] () -- C:\Windows\grep.exe
[2011/07/11 17:56:35 | 000,068,096 | R--- | C] () -- C:\Windows\zip.exe
[2011/07/04 18:31:34 | 000,000,035 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\SetValue.bat
[2011/07/04 18:31:33 | 000,000,691 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\GetValue.vbs
[2011/07/03 10:39:04 | 000,000,997 | ---- | C] () -- C:\Users\karoni\Application Data\Microsoft\Internet Explorer\Quick Launch\AnVir Task Manager Free.lnk
[2011/07/03 10:39:02 | 000,001,039 | ---- | C] () -- C:\Users\Public\Desktop\AnVir Task Manager Free.lnk
[2011/06/30 17:54:17 | 000,012,660 | ---- | C] () -- C:\Users\karoni\Documents\cc_20110630_175401.reg
[2011/06/26 02:45:56 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/06/24 18:14:15 | 000,002,135 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2011/06/24 18:14:15 | 000,002,123 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2011/06/24 18:08:53 | 000,001,203 | ---- | C] () -- C:\Users\karoni\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.8.lnk
[2011/06/24 18:08:52 | 000,001,179 | ---- | C] () -- C:\Users\karoni\Desktop\FrostWire 4.21.8.lnk
[2011/06/23 18:45:14 | 000,000,000 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\.googlewebacchosts
[2011/06/23 18:39:44 | 000,001,181 | ---- | C] () -- C:\Users\karoni\Desktop\Google Web Accelerator.lnk
[2011/06/23 18:23:27 | 000,001,965 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/06/20 20:35:19 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/20 20:35:19 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/03/20 13:42:53 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2010/12/22 21:22:02 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/11/09 21:50:41 | 000,000,017 | ---- | C] () -- C:\Users\karoni\AppData\Local\resmon.resmoncfg
[2010/10/13 19:17:07 | 000,007,887 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\pcouffin.cat
[2010/10/13 19:17:07 | 000,001,144 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\pcouffin.inf
[2010/10/10 18:19:03 | 000,001,041 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\vso_ts_preview.xml
[2010/10/10 11:22:41 | 000,000,039 | ---- | C] () -- C:\Windows\WININIT.INI
[2010/10/10 10:30:01 | 000,000,000 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\wklnhst.dat
[2010/04/24 19:18:07 | 000,000,279 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2010/04/24 18:48:38 | 000,021,316 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2010/04/17 17:01:27 | 000,000,000 | ---- | C] () -- C:\Windows\setup32.INI
[2010/02/12 23:21:31 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,389,408 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,624,178 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,106,522 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/11/06 07:02:10 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1114.dll
[2006/09/19 03:02:40 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/19 03:02:40 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/03/09 16:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2004/09/16 16:24:26 | 003,375,104 | ---- | C] () -- C:\Windows\System32\qt-mt331.dll
========== Custom Scans ========== < :OTL > < O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. > < O15 - HKU\S-1-5-21-1643368254-1818270169-1135579119-1000\..Trusted Domains: combofix.exe ([]* in Trusted sites) > < O15 - HKU\S-1-5-21-1643368254-1818270169-1135579119-1000\..Trusted Domains: infospyware.net ([www] http in Trusted sites) > < O15 - HKU\S-1-5-21-1643368254-1818270169-1135579119-1000\..Trusted Ranges: Range1 ([http] in Local intranet) > < O32 - AutoRun File - [2010/05/05 16:20:58 | 000,000,103 | ---- | M] () - F:\Autorun.inf -- [ FAT32 ] >Invalid Switch: 05 16:20:58 | 000,000,103 | ---- | M] () - F:\Autorun.inf -- [ FAT32 ]
< [2011/07/04 18:31:34 | 000,000,035 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\SetValue.bat >Invalid Switch: 04 18:31:34 | 000,000,035 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\SetValue.bat
< [2011/07/04 18:31:33 | 000,000,691 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\GetValue.vbs >Invalid Switch: 04 18:31:33 | 000,000,691 | ---- | C] () -- C:\Users\karoni\AppData\Roaming\GetValue.vbs
< > < :Services > < > < :Reg > < > < :Files > < > < :Commands > < [purity] > < [emptytemp] > < [EMPTYFLASH] > < [Reboot] >< End of report >