I am glad (or at least I hope) you know what your doing!
So I did the CFScript DeQuarantine routine and it ran Combo Fix....I also downloaded and ran the Gmer program....I had a problem upon completion of Gmer program and trying to end it. I closed Gmer. I then opened a Command Prompt. In the Command Prompt, I typed in "net stop gmer" and hit Enter. I got an error message (can't remember exactly what it said..but it didn't recognize the command). I also tried "stop gmer"...didn't recognize that either. Ultimately, I just typed in "exit" and closed the Command Prompt - Don't know if this is a problem or not.... (forgive my ignorance)
All of the requested logs are below:ComboFix 09-01-10.03 - Don 2009-01-12 20:44:36.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.243 [GMT -5:00]
Running from: c:\documents and settings\Don\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Don\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point
FILE ::
c:\windows\Tasks\orqxmheq.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Garrett\Application Data\uTorrent
c:\documents and settings\Garrett\Application Data\uTorrent\Avenged Sevenfold.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\BLINK182.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\dht.dat
c:\documents and settings\Garrett\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Garrett\Application Data\uTorrent\Halo Soundtrack [First, Second & Third].torrent
c:\documents and settings\Garrett\Application Data\uTorrent\HAWTHORNE HEIGHTS - DISCOGRAPHY [CHANNEL NEO].1.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\HAWTHORNE HEIGHTS - DISCOGRAPHY [CHANNEL NEO].torrent
c:\documents and settings\Garrett\Application Data\uTorrent\hentai. sex demon queen.avi.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\Live from the Hard Rock.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\My Chemical Romance.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\Prince.of.Persia-SKIDROW.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\Prince.of.Persia-SKIDROW[www.TmasGames.com].torrent
c:\documents and settings\Garrett\Application Data\uTorrent\resume.dat
c:\documents and settings\Garrett\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Garrett\Application Data\uTorrent\rss.dat
c:\documents and settings\Garrett\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Garrett\Application Data\uTorrent\settings.dat
c:\documents and settings\Garrett\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Garrett\Application Data\uTorrent\Simple Plan - Discografia.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\Simple Plan.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\sr-pop.iso.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\Sugarcult.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\The.Dark.Knight.2008.[Dual Audio] DVDRip.torrent
c:\documents and settings\Garrett\Application Data\uTorrent\We The Kings.torrent
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
c:\windows\system32\msrdo20.dll
c:\windows\system32\rdocurs.dll
c:\windows\Tasks\orqxmheq.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Usmbav
((((((((((((((((((((((((( Files Created from 2008-12-13 to 2009-01-13 )))))))))))))))))))))))))))))))
.
2009-01-03 14:36 . 2009-01-09 17:16 <DIR> d----c--- C:\rsit
2009-01-03 14:29 . 2009-01-07 19:07 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-03 14:29 . 2009-01-03 14:29 <DIR> d-------- c:\documents and settings\Don\Application Data\Malwarebytes
2009-01-03 14:29 . 2009-01-03 14:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-03 14:29 . 2009-01-04 18:38 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-03 14:29 . 2009-01-04 18:38 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-03 13:33 . 2009-01-03 13:33 <DIR> d-------- c:\program files\Trend Micro
2008-12-24 14:48 . 2008-12-24 14:48 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2008-12-21 12:00 . 2008-12-21 12:00 <DIR> d-------- c:\program files\Curse
2008-12-21 10:27 . 2008-12-21 10:27 <DIR> d-------- c:\documents and settings\Garrett\Application Data\Ventrilo
2008-12-21 10:26 . 2008-12-21 10:26 <DIR> d-------- c:\program files\Ventrilo
2008-12-21 10:26 . 2008-12-21 10:26 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-12 19:24 --------- d-----w c:\documents and settings\Garrett\Application Data\Xfire
2009-01-11 20:18 --------- d-----w c:\documents and settings\Garrett\Application Data\StumbleUpon
2009-01-11 18:15 --------- d-----w c:\program files\Java
2009-01-08 02:23 --------- d-----w c:\program files\Finale 2008 Demo
2009-01-07 20:06 --------- d-----w c:\documents and settings\Lisa\Application Data\StumbleUpon
2009-01-04 14:29 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2009-01-03 04:19 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-21 15:25 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-20 18:18 --------- d-----w c:\program files\Xfire
2008-12-13 02:07 --------- d-----w c:\program files\Norton Security Scan
2008-12-13 02:07 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-01 19:32 31 ----a-w c:\documents and settings\Garrett\jagex_runescape_preferences.dat
2008-11-28 16:44 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-28 16:42 --------- d-----w c:\program files\ScanSoft
2008-11-28 16:35 --------- d-----w c:\program files\MUSICMATCH
2008-11-28 16:33 --------- d-----w c:\program files\Pocket Tanks Deluxe
2008-11-28 16:30 --------- d-----w c:\program files\Warcraft III
2008-11-28 16:25 --------- d-----w c:\documents and settings\Garrett\Application Data\Hamachi
2008-11-26 23:57 --------- d-----w c:\program files\iTunes
2008-11-26 23:57 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-26 23:56 --------- d-----w c:\program files\iPod
2008-11-26 23:56 --------- d-----w c:\program files\Common Files\Apple
2008-11-26 00:37 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-11-25 22:38 --------- d-----w c:\program files\QuickTime
2008-11-24 19:52 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2008-08-19 11:40 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-10-28 23:36 27,976 ----a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-10-28 23:36 125,848 ----a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-10-28 23:36 98,712 ----a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2008-09-29 10:18 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008092920080930\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-11_14.07.59.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-11 18:05:29 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2009-01-13 01:27:48 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2009-01-11 18:05:29 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2009-01-13 01:27:48 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2009-01-13 01:56:06 16,384 ----atw c:\windows\TEMP\Perflib_Perfdata_1b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-21 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 323584]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-12-27 180269]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-16 1197648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992]
"ScanSoft OmniPage SE 4.0-reminder"="c:\program files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" [2006-09-26 1410600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-24 136600]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\SYSTEM32\narrator.exe]
c:\documents and settings\Garrett\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\xfire.exe [2008-12-11 2990416]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-12-25 113664]
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Will Workshop Deluxe 2004\\qlp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Garrett\\Desktop\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Documents and Settings\\Garrett\\Desktop\\World of Warcraft\\WoW-2.3.0-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\WINDOWS\\BCMSMMSG.exe"=
"c:\\Program Files\\AIM6\\aolsoftware.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\SYSTEM32\DRIVERS\ADM8511.SYS [2003-12-25 20160]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Mcafee\SiteAdvisor\McSACore.exe [2008-09-29 206096]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-02-25 24652]
S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\DRIVERS\LV532AV.SYS --> c:\windows\system32\DRIVERS\LV532AV.SYS [?]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\SYSTEM32\DRIVERS\usbbc.sys [2003-12-25 15576]
.
Contents of the 'Scheduled Tasks' folder
2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-08-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2007-03-17 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2009-01-11 c:\windows\Tasks\Norton Security Scan for Lisa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
2009-01-13 c:\windows\Tasks\User_Feed_Synchronization-{D8C6A76E-DD0C-4B03-B2DA-25F9D9A24B4E}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/ig?hl=enuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Google Search - c:\program files\google\GoogleToolbar3.dll/cmsearch.html
IE: &Search
IE: &Translate English Word - c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Backward Links - c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar3.dll/cmcache.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: Translate Page into English - c:\program files\google\GoogleToolbar3.dll/cmtrans.html
Trusted Zone: nuxmail4.nu.com
Trusted Zone: *.turbotax.com
FF - ProfilePath - c:\documents and settings\Don\Application Data\Mozilla\Firefox\Profiles\ky24vzqx.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/ig?hl=enFF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-12 20:57:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\SYSTEM32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\Mcafee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\Mcafee\VIRUSS~1\Mcshield.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\MsPMSPSv.exe
c:\windows\SYSTEM32\fxssvc.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Mcafee\MPF\MpfSrv.exe
c:\progra~1\Mcafee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-01-12 21:09:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-13 02:09:15
ComboFix2.txt 2009-01-11 19:10:16
C:\DeQuarantine.txt
Pre-Run: 15,835,611,136 bytes free
Post-Run: 15,835,078,656 bytes free
269 --- E O F --- 2008-12-19 03:09:03
-------------------------------------
Here is the ComboFix DeQuarantine Log:C:\Qoobox\Quarantine\C\Windows\system32\msrdo20.dll.vir -> C:\Windows\system32\msrdo20.dll ( 397312 bytes )
C:\Qoobox\Quarantine\C\Windows\system32\rdocurs.dll.vir -> C:\Windows\system32\rdocurs.dll ( 151552 bytes )
--------------------------------------
Here is the Gmer Log:
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2009-01-12 21:51:29
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEED389AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEED38958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEED3896C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEED389EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEED38930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEED38944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEED389BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEED38996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEED38982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEED38A19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEED38A00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEED389D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.14 ----
.text ntoskrnl.exe!ZwYieldExecution 804F0EA6 7 Bytes JMP EED389D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056CDC0 5 Bytes JMP EED389AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056DC01 5 Bytes JMP EED38986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 805717C7 5 Bytes JMP EED38934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80571CB1 7 Bytes JMP EED389C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 805736E6 5 Bytes JMP EED38A04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80573B61 7 Bytes JMP EED389EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FC6C 7 Bytes JMP EED38970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805822EC 5 Bytes JMP EED38A1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058A1C9 5 Bytes JMP EED38948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B136A 5 Bytes JMP EED3895C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062DCF7 5 Bytes JMP EED3899A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? Combo-Fix.sys The system cannot find the file specified. !
? C:\ComboFix\catchme.sys The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.14 ----
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[696] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[696] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01030FE5
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 010300AB
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0103009A
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01030073
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01030058
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01030047
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 010300C6
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01030F74
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01030F3E
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010300E1
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01030F2D
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01030FB6
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01030000
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01030F91
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01030036
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0103001B
.text C:\WINDOWS\system32\services.exe[856] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01030F63
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0102000A
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01020F83
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01020FB9
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 01020FD4
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01020040
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01020FEF
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 01020F94
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 22, 89 ]
.text C:\WINDOWS\system32\services.exe[856] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 0102001B
.text C:\WINDOWS\system32\services.exe[856] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F10FE5
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F10064
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F10F6F
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F1003D
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F1002C
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F100B7
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F10090
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F100F4
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F100E3
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00F10F40
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00F10011
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F10FD4
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00F1007F
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00F10F9E
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00F10FAF
.text C:\WINDOWS\system32\lsass.exe[868] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00F100D2
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00F00FCA
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00F00F97
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00F0001B
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00F00FA8
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00F00000
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00F00FB9
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 10, 89 ]
.text C:\WINDOWS\system32\lsass.exe[868] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00F00036
.text C:\WINDOWS\system32\lsass.exe[868] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00EA0000
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00AD0FE5
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00AD0F4B
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00AD0F5C
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00AD0F83
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00AD0040
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00AD0FB9
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00AD0F1F
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00AD005B
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00AD0ED8
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00AD0EE9
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00AD0EBD
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00AD0F9E
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00AD0FD4
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00AD0F3A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00AD001B
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00AD000A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00AD0F0E
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00AC0FC0
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00AC002C
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00AC0011
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00AC0000
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00AC0F6F
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00AC0FE5
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00AC0F8A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ CC, 88 ]
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00AC0FA5
.text C:\WINDOWS\system32\svchost.exe[1056] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A80FE5
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C10000
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C10F8A
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C10F9B
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C10073
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C10FB6
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C10047
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C100BF
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C10F6D
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C10110
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C100EB
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C1012B
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C10058
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C1001B
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C100A4
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C10FDB
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C1002C
.text C:\WINDOWS\system32\svchost.exe[1104] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C100DA
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00C0001B
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00C00065
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00C0000A
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00C00FCA
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00C00FA8
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00C00FE5
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00C00040
.text C:\WINDOWS\system32\svchost.exe[1104] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00C00FB9
.text C:\WINDOWS\system32\svchost.exe[1104] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BE0000
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 025D0000
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 025D0058
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 025D0F63
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 025D0F74
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 025D003D
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 025D0FA5
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 025D0097
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 025D007A
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 025D00C3
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 025D0F2A
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 025D00D4
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 025D002C
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 025D0FE5
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 025D0069
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 025D001B
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 025D0FCA
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 025D00A8
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 025B0FA5
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 025B003D
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 025B0000
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 025B0FD4
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 025B002C
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 025B0FE5
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 025B0F94
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 7B, 8A ]
.text C:\WINDOWS\System32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 025B0011
.text C:\WINDOWS\System32\svchost.exe[1244] WS2_32.dll!socket 71AB4211 5 Bytes JMP 023D0FEF
.text C:\WINDOWS\System32\svchost.exe[1244] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 025C0FEF
.text C:\WINDOWS\System32\svchost.exe[1244] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 025C000A
.text C:\WINDOWS\System32\svchost.exe[1244] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 025C0FD4
.text C:\WINDOWS\System32\svchost.exe[1244] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 025C0FB9
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0078000A
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00780F94
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00780FAF
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00780FC0
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0078007D
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00780FDB
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00780F4D
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00780F5E
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007800C1
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007800B0
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00780F0D
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00780062
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0078001B
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00780F79
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00780047
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00780036
.text C:\WINDOWS\System32\svchost.exe[1300] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00780F3C
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00770036
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00770FA5
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00770025
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0077000A
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00770FC0
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00770FEF
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00770062
.text C:\WINDOWS\System32\svchost.exe[1300] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00770047
.text C:\WINDOWS\System32\svchost.exe[1300] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006C0FEF
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CE0000
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CE0098
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CE0087
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CE006C
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CE005B
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CE002F
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CE0F64
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CE0F75
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CE0F24
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CE00BD
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00CE00D8
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00CE0040
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00CE0FE5
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00CE0F92
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00CE0FC3
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00CE0F49
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 009D0FB9
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 009D0F8D
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 009D0014
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 009D0FDE
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 009D0040
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 009D0FEF
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 009D0F9E
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ BD, 88 ]
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 009D0025
.text C:\WINDOWS\system32\svchost.exe[1348] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009B000A
.text C:\WINDOWS\system32\svchost.exe[1348] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 009E0FEF
.text C:\WINDOWS\system32\svchost.exe[1348] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 009E000A
.text C:\WINDOWS\system32\svchost.exe[1348] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 009E0FCA
.text C:\WINDOWS\system32\svchost.exe[1348] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 009E0FB9
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B50000
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B50075
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B50F80
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B5005A
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B50033
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B50F9B
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B5009A
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B50F52
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B500BC
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B50F2D
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00B50F08
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00B50022
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00B50011
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00B50F6F
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00B50FC0
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00B50FD1
.text C:\WINDOWS\System32\svchost.exe[1792] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00B500AB
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00B40FD4
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00B40F90
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00B40025
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00B40FEF
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00B40FA1
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00B40000
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00B40FB2
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ D4, 88 ]
.text C:\WINDOWS\System32\svchost.exe[1792] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00B40FC3
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01210FEF
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01210F7A
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0121006F
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0121005E
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01210FA1
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01210FC3
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 012100B8
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0121009B
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 012100D3
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01210F3A
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01210F1F
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01210FB2
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0121000A
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 0121008A
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01210FD4
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 01210025
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01210F5F
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 01200047
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01200098
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 0120002C
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0120001B
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01200FDB
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01200000
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 01200073
.text C:\WINDOWS\system32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 01200062
.text C:\WINDOWS\system32\svchost.exe[2028] WS2_32.dll!socket 71AB4211 5 Bytes JMP 011E0FE5
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0084
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0F8F
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0069
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0FAC
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0033
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A00B0
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A009F
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A00F0
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F57
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A0F3C
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0044
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0011
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0F74
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FC7
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0022
.text C:\WINDOWS\explorer.exe[2568] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A00D5
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00290FCD
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 0029005E
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FDE
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00290FEF
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290043
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290000
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00290FAB
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 49, 88 ]
.text C:\WINDOWS\explorer.exe[2568] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290FBC
.text C:\WINDOWS\explorer.exe[2568] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C0000
.text C:\WINDOWS\explorer.exe[2568] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C0FE5
.text C:\WINDOWS\explorer.exe[2568] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C001B
.text C:\WINDOWS\explorer.exe[2568] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002C0FC0
.text C:\WINDOWS\explorer.exe[2568] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0062
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0F6D
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0F88
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0051
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0025
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A008E
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A007D
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A00DF
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A00C4
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A00F0
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0040
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0FDE
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0F5C
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FC3
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0014
.text C:\WINDOWS\System32\svchost.exe[3788] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A00A9
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00290FA5
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290F68
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FC0
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00290000
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290F79
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290FE5
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 0029001B
.text C:\WINDOWS\System32\svchost.exe[3788] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290F94
.text C:\WINDOWS\System32\svchost.exe[3788] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006E0000
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- Registry - GMER 1.0.14 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{101124FA-FFBB-531A-857D-17BCB9C0E544}\InprocServer32@ C:\Program Files\Canon\ZoomBrowser EX\Program\utilities.dll
---- EOF - GMER 1.0.14 ----