Hello Adam,
All of those went well except when typing net stop gmer into command prompt I revieved the message - the specific service does not exist as an installed service. Here are the GMER log, Kaspersky report and the new Hijackthis log (I have had to split them to keep each post within the characters limit):
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-10 21:21:20
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT spfp.sys ZwCreateKey [0xF72BD0E0]
SSDT spfp.sys ZwEnumerateKey [0xF72DBCA4]
SSDT spfp.sys ZwEnumerateValueKey [0xF72DC032]
SSDT spfp.sys ZwOpenKey [0xF72BD0C0]
SSDT spfp.sys ZwQueryKey [0xF72DC10A]
SSDT spfp.sys ZwQueryValueKey [0xF72DBF8A]
SSDT spfp.sys ZwSetValueKey [0xF72DC19C]
INT 0x62 ? 86DD8BF8
INT 0x63 ? 86DD8BF8
INT 0x63 ? 86DD8BF8
INT 0x63 ? 86DD8BF8
INT 0x84 ? 86C1BBF8
INT 0x94 ? 86C1BBF8
INT 0xA4 ? 86C1BBF8
INT 0xB4 ? 86C1BBF8
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA9C774EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA9C77498]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xA9C774AC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA9C7752A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xA9C77470]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xA9C77484]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA9C774FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xA9C774D6]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xA9C774C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA9C77559]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA9C77540]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA9C77514]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP A9C77518 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP A9C774EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP A9C7752E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP A9C77544 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP A9C77502 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB408 5 Bytes JMP A9C77474 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB694 5 Bytes JMP A9C77488 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE52 5 Bytes JMP A9C774C6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1142 7 Bytes JMP A9C774B0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11F8 5 Bytes JMP A9C7749C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D1702 5 Bytes JMP A9C774DA \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29AA 5 Bytes JMP A9C7755D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? spfp.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F67888AC 5 Bytes JMP 86C1B1D8
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E72B80
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E72B3D
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E72B01
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E72AE6
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E72972
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E72A64
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E729AA
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[180] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E729E2
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00FE2B80
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00FE2B3D
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00FE2B01
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00FE2AE6
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00FE2972
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00FE2A64
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00FE29AA
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[256] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00FE29E2
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01132B80
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01132B3D
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01132B01
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01132AE6
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01132972
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01132A64
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] WS2_32.dll!recv 71AB676F 5 Bytes JMP 011329AA
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[320] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 011329E2
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 018B2B80
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 018B2B3D
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 018B2B01
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 018B2AE6
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] WS2_32.dll!send 71AB4C27 5 Bytes JMP 018B2972
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 018B2A64
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] WS2_32.dll!recv 71AB676F 5 Bytes JMP 018B29AA
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[400] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 018B29E2
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01E00FEF
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01E00093
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01E00078
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01E00F9E
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01E00FAF
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01E0005B
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01E000CB
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01E000AE
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01E00F4D
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01E00F68
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01E00101
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01E00FCA
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01E00014
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01E00F83
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01E00040
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01E00025
.text C:\WINDOWS\system32\services.exe[724] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01E000E6
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01CA002F
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01CA005B
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01CA0FDE
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01CA0014
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01CA004A
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01CA0FEF
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01CA0FA8
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes JMP 50C03389
.text C:\WINDOWS\system32\services.exe[724] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01CA0FC3
.text C:\WINDOWS\system32\services.exe[724] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01C90047
.text C:\WINDOWS\system32\services.exe[724] msvcrt.dll!system 77C293C7 5 Bytes JMP 01C90036
.text C:\WINDOWS\system32\services.exe[724] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01C90FC6
.text C:\WINDOWS\system32\services.exe[724] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01C90000
.text C:\WINDOWS\system32\services.exe[724] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01C90025
.text C:\WINDOWS\system32\services.exe[724] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01C90FE3
.text C:\WINDOWS\system32\services.exe[724] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01C8000A
.text C:\WINDOWS\system32\services.exe[724] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 01CB0000
.text C:\WINDOWS\system32\services.exe[724] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 01CB0FE5
.text C:\WINDOWS\system32\services.exe[724] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 01CB001B
.text C:\WINDOWS\system32\services.exe[724] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 01CB0FCA
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F50000
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F5009A
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F50089
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F50FAF
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F50062
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F50040
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F50F94
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F500DC
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F50F4D
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F50F68
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F50F3C
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F50051
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F50FE5
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F500B5
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F50025
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F50FD4
.text C:\WINDOWS\system32\lsass.exe[736] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F50F79
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F40FDB
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F4006C
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F4002C
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F4001B
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F4005B
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F4000A
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F40FB9
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [14, 89] {ADC AL, 0x89}
.text C:\WINDOWS\system32\lsass.exe[736] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F40FCA
.text C:\WINDOWS\system32\lsass.exe[736] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F3004C
.text C:\WINDOWS\system32\lsass.exe[736] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F30FB7
.text C:\WINDOWS\system32\lsass.exe[736] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F30FD2
.text C:\WINDOWS\system32\lsass.exe[736] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F30000
.text C:\WINDOWS\system32\lsass.exe[736] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F30027
.text C:\WINDOWS\system32\lsass.exe[736] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F30FE3
.text C:\WINDOWS\system32\lsass.exe[736] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BF000A
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 015A2B80
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 015A2B3D
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 015A2B01
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 015A2AE6
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] WS2_32.dll!send 71AB4C27 5 Bytes JMP 015A2972
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 015A2A64
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] WS2_32.dll!recv 71AB676F 5 Bytes JMP 015A29AA
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[792] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 015A29E2
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02690FE5
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02690064
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02690F6F
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02690053
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02690F8A
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02690036
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 026900A6
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02690095
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 026900D9
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 026900C8
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02690F25
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02690FA5
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02690FD4
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02690F5E
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02690025
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0269000A
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 026900B7
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02670FD4
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02670F9E
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02670FEF
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02670025
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0267005B
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0267000A
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 02670FC3
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [87, 8A]
.text C:\WINDOWS\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02670040
.text C:\WINDOWS\system32\svchost.exe[948] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02660055
.text C:\WINDOWS\system32\svchost.exe[948] msvcrt.dll!system 77C293C7 5 Bytes JMP 02660FD4
.text C:\WINDOWS\system32\svchost.exe[948] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02660044
.text C:\WINDOWS\system32\svchost.exe[948] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02660000
.text C:\WINDOWS\system32\svchost.exe[948] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02660FEF
.text C:\WINDOWS\system32\svchost.exe[948] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02660029
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02650000
.text C:\WINDOWS\system32\svchost.exe[948] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 02680000
.text C:\WINDOWS\system32\svchost.exe[948] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 0268001B
.text C:\WINDOWS\system32\svchost.exe[948] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 0268002C
.text C:\WINDOWS\system32\svchost.exe[948] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 02680FDB
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01482B80
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01482B3D
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01482B01
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01482AE6
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01482972
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01482A64
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] WS2_32.dll!recv 71AB676F 5 Bytes JMP 014829AA
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1052] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 014829E2
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0105000A
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01050F66
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0105005B
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01050F8D
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01050FA8
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0105004A
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0105009B
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01050080
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01050F13
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010500AC
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 010500C7
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01050FC3
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0105001B
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01050F55
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01050FDE
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01050FEF
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01050F38
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01030025
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01030F8A
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0103000A
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01030FD4
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01030047
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01030FEF
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01030FA5
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [23, 89]
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01030036
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0102002F
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!system 77C293C7 5 Bytes JMP 01020FA4
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01020FB5
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01020FEF
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01020014
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01020FC6
.text C:\WINDOWS\system32\svchost.exe[1072] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0101000A
.text C:\WINDOWS\system32\svchost.exe[1072] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 01040FEF
.text C:\WINDOWS\system32\svchost.exe[1072] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 01040000
.text C:\WINDOWS\system32\svchost.exe[1072] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 01040FC0
.text C:\WINDOWS\system32\svchost.exe[1072] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 01040FAF
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 05BB0000
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 05BB0F9E
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 05BB0089
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 05BB0FAF
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 05BB0FC0
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 05BB0047
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 05BB00BF
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 05BB0F83
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 05BB00D0
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 05BB0F41
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 05BB00E1
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 05BB0058
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 05BB0011
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 05BB00AE
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 05BB0FD1
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 05BB002C
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 05BB0F5C
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 3 Bytes JMP 0569001B
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyExW + 4 77DD6AB3 1 Byte [8D]
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyExW 77DD776C 3 Bytes JMP 05690F8D
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyExW + 4 77DD7770 1 Byte [8D]
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyExA 77DD7852 3 Bytes JMP 05690FD4
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyExA + 4 77DD7856 1 Byte [8D]
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyW 77DD7946 3 Bytes JMP 05690FE5
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyW + 4 77DD794A 1 Byte [8D]
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 3 Bytes JMP 05690F9E
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyExA + 4 77DDE9F8 1 Byte [8D]
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 3 Bytes JMP 0569000A
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyA + 4 77DDEFCC 1 Byte [8D]
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 05690040
.text C:\WINDOWS\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 05690FB9
.text C:\WINDOWS\System32\svchost.exe[1168] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 052C0027
.text C:\WINDOWS\System32\svchost.exe[1168] msvcrt.dll!system 77C293C7 5 Bytes JMP 052C0FA6
.text C:\WINDOWS\System32\svchost.exe[1168] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 052C0FD2
.text C:\WINDOWS\System32\svchost.exe[1168] msvcrt.dll!_open 77C2F566 5 Bytes JMP 052C0000
.text C:\WINDOWS\System32\svchost.exe[1168] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 052C0FB7
.text C:\WINDOWS\System32\svchost.exe[1168] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 052C0FE3
.text C:\WINDOWS\System32\svchost.exe[1168] WS2_32.dll!socket 71AB4211 5 Bytes JMP 052B0000
.text C:\WINDOWS\System32\svchost.exe[1168] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 056A0000
.text C:\WINDOWS\System32\svchost.exe[1168] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 056A0011
.text C:\WINDOWS\System32\svchost.exe[1168] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 056A0022
.text C:\WINDOWS\System32\svchost.exe[1168] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 056A0FD1
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00BE2B80
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00BE2B3D
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00BE2B01
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BE2AE6
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BE2972
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BE2A64
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BE29AA
.text C:\Program Files\iTunes\iTunesHelper.exe[1264] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BE29E2
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00C32B80
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00C32B3D
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00C32B01
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C32AE6
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C32972
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C32A64
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C329AA
.text C:\Program Files\Java\jre6\bin\jusched.exe[1320] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C329E2
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A10FEF
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10081
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A10F8C
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10070
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A1005F
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A1003D
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A10F5B
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A100A3
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A10F14
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A10F2F
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A10F03
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A1004E
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A1000A
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A10092
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A1002C
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A1001B
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A10F40
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A00FBC
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A00054
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A00FCD
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A00FDE
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A00043
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A00FEF
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A00FA1
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C0, 88]
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A00028
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009F0FAD
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!system 77C293C7 5 Bytes JMP 009F0FBE
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009F001D
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009F0FE3
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009F002E
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009F000C
.text C:\WINDOWS\system32\svchost.exe[1348] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006C0FEF
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01262B80
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01262B3D
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01262B01
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01262AE6
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01262972
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01262A64
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012629AA
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[1500] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012629E2
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02622AE6
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02622972
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02622A64
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] WS2_32.dll!recv 71AB676F 5 Bytes JMP 026229AA
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 026229E2
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02622B80
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02622B3D
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1604] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02622B01
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02850FE5
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02850084
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02850F8F
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02850069
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02850FAC
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0285003D
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 028500C1
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 028500B0
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02850F43
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 028500E6
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02850F28
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0285004E
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02850000
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0285009F
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0285002C
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02850011
.text C:\WINDOWS\Explorer.EXE[1740] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02850F68
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02770036
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02770FA5
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02770025
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02770FEF
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02770062
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02770000
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01842B80
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01842B3D
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01842B01
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02770051
.text C:\WINDOWS\Explorer.EXE[1740] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02770FCA
.text C:\WINDOWS\Explorer.EXE[1740] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02750F9E
.text C:\WINDOWS\Explorer.EXE[1740] msvcrt.dll!system 77C293C7 5 Bytes JMP 02750029
.text C:\WINDOWS\Explorer.EXE[1740] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02750018
.text C:\WINDOWS\Explorer.EXE[1740] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02750FEF
.text C:\WINDOWS\Explorer.EXE[1740] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02750FC3
.text C:\WINDOWS\Explorer.EXE[1740] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02750FDE
.text C:\WINDOWS\Explorer.EXE[1740] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 0284000A
.text C:\WINDOWS\Explorer.EXE[1740] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 02840FEF
.text C:\WINDOWS\Explorer.EXE[1740] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 02840025
.text C:\WINDOWS\Explorer.EXE[1740] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 02840FDE
.text C:\WINDOWS\Explorer.EXE[1740] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01842AE6
.text C:\WINDOWS\Explorer.EXE[1740] WS2_32.dll!socket 71AB4211 5 Bytes JMP 017F0FEF
.text C:\WINDOWS\Explorer.EXE[1740] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01842972
.text C:\WINDOWS\Explorer.EXE[1740] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01842A64
.text C:\WINDOWS\Explorer.EXE[1740] WS2_32.dll!recv 71AB676F 5 Bytes JMP 018429AA
.text C:\WINDOWS\Explorer.EXE[1740] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 018429E2
.text C:\WINDOWS\eHome\ehmsas.exe[1852] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00CD2B80
.text C:\WINDOWS\eHome\ehmsas.exe[1852] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00CD2B3D
.text C:\WINDOWS\eHome\ehmsas.exe[1852] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00CD2B01
.text C:\WINDOWS\eHome\ehmsas.exe[1852] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00CD2AE6
.text C:\WINDOWS\eHome\ehmsas.exe[1852] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00CD2972
.text C:\WINDOWS\eHome\ehmsas.exe[1852] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00CD2A64
.text C:\WINDOWS\eHome\ehmsas.exe[1852] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00CD29AA
.text C:\WINDOWS\eHome\ehmsas.exe[1852] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00CD29E2
.text C:\WINDOWS\ehome\ehtray.exe[1980] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 012E2B80
.text C:\WINDOWS\ehome\ehtray.exe[1980] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 012E2B3D
.text C:\WINDOWS\ehome\ehtray.exe[1980] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 012E2B01
.text C:\WINDOWS\ehome\ehtray.exe[1980] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012E2AE6
.text C:\WINDOWS\ehome\ehtray.exe[1980] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012E2972
.text C:\WINDOWS\ehome\ehtray.exe[1980] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012E2A64
.text C:\WINDOWS\ehome\ehtray.exe[1980] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012E29AA
.text C:\WINDOWS\ehome\ehtray.exe[1980] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012E29E2
.text C:\WINDOWS\system32\hkcmd.exe[2000] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DA2B80
.text C:\WINDOWS\system32\hkcmd.exe[2000] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DA2B3D
.text C:\WINDOWS\system32\hkcmd.exe[2000] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DA2B01
.text C:\WINDOWS\system32\hkcmd.exe[2000] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DA2AE6
.text C:\WINDOWS\system32\hkcmd.exe[2000] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DA2972
.text C:\WINDOWS\system32\hkcmd.exe[2000] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DA2A64
.text C:\WINDOWS\system32\hkcmd.exe[2000] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DA29AA
.text C:\WINDOWS\system32\hkcmd.exe[2000] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DA29E2
.text C:\WINDOWS\system32\igfxpers.exe[2012] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00D92B80
.text C:\WINDOWS\system32\igfxpers.exe[2012] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00D92B3D
.text C:\WINDOWS\system32\igfxpers.exe[2012] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00D92B01
.text C:\WINDOWS\system32\igfxpers.exe[2012] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00D92AE6
.text C:\WINDOWS\system32\igfxpers.exe[2012] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00D92972
.text C:\WINDOWS\system32\igfxpers.exe[2012] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00D92A64
.text C:\WINDOWS\system32\igfxpers.exe[2012] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00D929AA
.text C:\WINDOWS\system32\igfxpers.exe[2012] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00D929E2
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 010B2B80
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 010B2B3D
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 010B2B01
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 010B2AE6
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] WS2_32.dll!send 71AB4C27 5 Bytes JMP 010B2972
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 010B2A64
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] WS2_32.dll!recv 71AB676F 5 Bytes JMP 010B29AA
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[2036] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 010B29E2
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C50FEF
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C50036
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C50F4B
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C50F68
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C50F83
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C5001B
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C50F15
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C5005D
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C50ECE
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C50EE9
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C50EBD
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C50F94
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C50FCA
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C50F30
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C5000A
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C50FB9
.text C:\WINDOWS\system32\svchost.exe[2056] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C50EFA
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C3002F
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C30F86
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C30FD4
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C30FE5
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C30F97
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C30000
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C30FB2
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [E3, 88] {JECXZ 0xffffffffffffff8a}
.text C:\WINDOWS\system32\svchost.exe[2056] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C30FC3
.text C:\WINDOWS\system32\svchost.exe[2056] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C2005D
.text C:\WINDOWS\system32\svchost.exe[2056] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C20042
.text C:\WINDOWS\system32\svchost.exe[2056] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C20FD2
.text C:\WINDOWS\system32\svchost.exe[2056] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C2000C
.text C:\WINDOWS\system32\svchost.exe[2056] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C20027
.text C:\WINDOWS\system32\svchost.exe[2056] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\system32\svchost.exe[2056] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 00C40000
.text C:\WINDOWS\system32\svchost.exe[2056] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 00C40011
.text C:\WINDOWS\system32\svchost.exe[2056] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 00C40022
.text C:\WINDOWS\system32\svchost.exe[2056] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 00C40033
.text C:\WINDOWS\system32\svchost.exe[2056] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C1000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C12AE6
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C12972
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C12A64
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C129AA
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C129E2
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00C12B80
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00C12B3D
.text C:\Program Files\Bonjour\mDNSResponder.exe[2112] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00C12B01
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A002F
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0F3A
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0F4B
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0F68
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0F94
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0F0C
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F29
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0ECF
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0EE0
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001A0EB4
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001A0F79
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001A0FCA
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001A004A
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001A000A
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001A0FB9
.text C:\WINDOWS\System32\svchost.exe[2132] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001A0EFB
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00290FCA
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0029007D
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0029001B
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0029000A
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0029006C
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00290FEF
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00290051
.text C:\WINDOWS\System32\svchost.exe[2132] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00290036
.text C:\WINDOWS\System32\svchost.exe[2132] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003E0FB7
.text C:\WINDOWS\System32\svchost.exe[2132] msvcrt.dll!system 77C293C7 5 Bytes JMP 003E0FC8
.text C:\WINDOWS\System32\svchost.exe[2132] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003E002E
.text C:\WINDOWS\System32\svchost.exe[2132] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003E000C
.text C:\WINDOWS\System32\svchost.exe[2132] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003E0FD9
.text C:\WINDOWS\System32\svchost.exe[2132] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003E001D
.text C:\WINDOWS\System32\svchost.exe[2132] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006E0FEF
.text C:\WINDOWS\System32\svchost.exe[2132] WININET.dll!InternetOpenA 7806C879 5 Bytes JMP 01010FE5
.text C:\WINDOWS\System32\svchost.exe[2132] WININET.dll!InternetOpenW 7806CEA9 5 Bytes JMP 01010000
.text C:\WINDOWS\System32\svchost.exe[2132] WININET.dll!InternetOpenUrlA 78070BD2 5 Bytes JMP 01010FCA
.text C:\WINDOWS\System32\svchost.exe[2132] WININET.dll!InternetOpenUrlW 780BB079 5 Bytes JMP 01010FAF
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00D02B80
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00D02B3D
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00D02B01
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00D02AE6
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00D02972
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00D02A64
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00D029AA
.text C:\WINDOWS\eHome\ehRecvr.exe[2156] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00D029E2
.text C:\WINDOWS\eHome\ehSched.exe[2168] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00AC2B80
.text C:\WINDOWS\eHome\ehSched.exe[2168] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00AC2B3D
.text C:\WINDOWS\eHome\ehSched.exe[2168] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00AC2B01
.text C:\WINDOWS\eHome\ehSched.exe[2168] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00AC2AE6
.text C:\WINDOWS\eHome\ehSched.exe[2168] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00AC2972
.text C:\WINDOWS\eHome\ehSched.exe[2168] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00AC2A64
.text C:\WINDOWS\eHome\ehSched.exe[2168] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00AC29AA
.text C:\WINDOWS\eHome\ehSched.exe[2168] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00AC29E2
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00B32B80
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00B32B3D
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00B32B01
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00B32AE6
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B32972
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00B32A64
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00B329AA
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2396] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00B329E2
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01152B80
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01152B3D
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01152B01
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01152AE6
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01152972
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01152A64
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] WS2_32.dll!recv 71AB676F 5 Bytes JMP 011529AA
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[2600] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 011529E2
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01912AE6
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01912972
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01912A64
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] WS2_32.dll!recv 71AB676F 5 Bytes JMP 019129AA
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 019129E2
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01912B80
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01912B3D
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2684] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01912B01
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01522AE6
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01522972
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01522A64
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] WS2_32.dll!recv 71AB676F 5 Bytes JMP 015229AA
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 015229E2
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01522B80
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01522B3D
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2704] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01522B01
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 023C2B80
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 023C2B3D
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 023C2B01
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 023C2AE6
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] WS2_32.dll!send 71AB4C27 5 Bytes JMP 023C2972
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 023C2A64
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] WS2_32.dll!recv 71AB676F 5 Bytes JMP 023C29AA
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2756] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 023C29E2
.text C:\Program Files\iPod\bin\iPodService.exe[2816] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00BD2B80
.text C:\Program Files\iPod\bin\iPodService.exe[2816] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00BD2B3D
.text C:\Program Files\iPod\bin\iPodService.exe[2816] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00BD2B01
.text C:\Program Files\iPod\bin\iPodService.exe[2816] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BD2AE6
.text C:\Program Files\iPod\bin\iPodService.exe[2816] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BD2972
.text C:\Program Files\iPod\bin\iPodService.exe[2816] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BD2A64
.text C:\Program Files\iPod\bin\iPodService.exe[2816] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BD29AA
.text C:\Program Files\iPod\bin\iPodService.exe[2816] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BD29E2