Thank you for your time, it is much appreciated.
The following GMER log was in notepad twice. I saved the two sections separately, then did a compare with fc. They were identical, so I only posted one. Maybe I pasted it in twice. Another HJT log follows in another post.
Here's the GMER log:
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-05-03 06:26:24
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwCreateKey [0xF842D0D0]
SSDT sptd.sys ZwEnumerateKey [0xF8432FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF8433340]
SSDT sptd.sys ZwOpenKey [0xF842D0B0]
SSDT sptd.sys ZwQueryKey [0xF8433418]
SSDT sptd.sys ZwQueryValueKey [0xF8433298]
SSDT sptd.sys ZwSetValueKey [0xF84334AA]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEFC1BF20]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEFB374EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEFB37498]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEFB374AC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xEFB3759B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xEFB375C7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEFB3752A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEFB37661]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEFB37470]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEFB37484]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEFB374FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEFB37609]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEFB375B1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEFB37689]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEFB37675]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEFB374D6]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEFB374C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEFB37559]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEFB3764B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEFB37540]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEFB37514]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution 804F8B8D 7 Bytes JMP EFB37518 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056BDCD 5 Bytes JMP EFB374C6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056FC78 5 Bytes JMP EFB374EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 80571F71 2 Bytes JMP EFB37544 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection + 3 80571F74 2 Bytes [5C, 6F] {POP ESP; OUTSD }
PAGE ntoskrnl.exe!NtMapViewOfSection 805723EC 7 Bytes JMP EFB3752E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 80572D86 5 Bytes JMP EFB37474 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80573135 7 Bytes JMP EFB37502 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 80581F0E 7 Bytes JMP EFB374B0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805847CC 5 Bytes JMP EFB3755D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058C892 5 Bytes JMP EFB37488 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 80590EA2 5 Bytes JMP EFB37665 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80593B38 7 Bytes JMP EFB375CB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 805951C2 7 Bytes JMP EFB3759F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B0B34 5 Bytes JMP EFB3749C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062C4B3 5 Bytes JMP EFB374DA \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8064C148 5 Bytes JMP EFB37679 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 8064C421 7 Bytes JMP EFB3764F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 8064CCF0 7 Bytes JMP EFB3760D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064D137 7 Bytes JMP EFB375B5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8064D62A 5 Bytes JMP EFB3768D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F81DB62C 5 Bytes JMP 8220F770
? System32\Drivers\a1fsqa07.SYS The system cannot find the path specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 007F0FEF
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 007F0F69
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 007F0F7A
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 007F0054
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 007F0F97
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 007F0FA8
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 007F00B1
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 007F008A
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007F0F3D
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 007F0F4E
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 007F0F2C
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 007F002F
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 007F0FDE
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 007F0079
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 007F001E
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 007F0FCD
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 007F00CC
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 007E0FE5
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 007E0F8A
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegOpenKeyExA 77DD7832 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 007E0036
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 007E0025
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 007E0FAF
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 007E0000
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 007E0051
.text C:\WINDOWS\System32\svchost.exe[196] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 007E0FD4
.text C:\WINDOWS\System32\svchost.exe[196] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 007D0055
.text C:\WINDOWS\System32\svchost.exe[196] msvcrt.dll!system 77C293C7 5 Bytes JMP 007D0044
.text C:\WINDOWS\System32\svchost.exe[196] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 007D0018
.text C:\WINDOWS\System32\svchost.exe[196] msvcrt.dll!_open 77C2F566 5 Bytes JMP 007D0FEF
.text C:\WINDOWS\System32\svchost.exe[196] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 007D0033
.text C:\WINDOWS\System32\svchost.exe[196] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 007D0FDE
.text C:\WINDOWS\System32\svchost.exe[196] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007B0FEF
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 015E0000
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 015E007F
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 015E0F94
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 015E0062
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 015E0FAF
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 015E0051
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 015E00A1
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 015E0090
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 015E00D4
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 015E00C3
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 015E00E5
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 015E0FCA
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 015E0011
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 015E0F6F
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 015E0040
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 015E0FE5
.text C:\WINDOWS\Explorer.EXE[584] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 015E00B2
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 015C0011
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 015C0051
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 015C0000
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 015C0FCA
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 015C0F8A
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 015C0FEF
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 015C0FAF
.text C:\WINDOWS\Explorer.EXE[584] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 015C0036
.text C:\WINDOWS\Explorer.EXE[584] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 015B0049
.text C:\WINDOWS\Explorer.EXE[584] msvcrt.dll!system 77C293C7 5 Bytes JMP 015B0FBE
.text C:\WINDOWS\Explorer.EXE[584] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 015B001D
.text C:\WINDOWS\Explorer.EXE[584] msvcrt.dll!_open 77C2F566 5 Bytes JMP 015B0FEF
.text C:\WINDOWS\Explorer.EXE[584] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 015B002E
.text C:\WINDOWS\Explorer.EXE[584] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 015B000C
.text C:\WINDOWS\Explorer.EXE[584] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 015D0000
.text C:\WINDOWS\Explorer.EXE[584] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 015D001B
.text C:\WINDOWS\Explorer.EXE[584] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 015D0036
.text C:\WINDOWS\Explorer.EXE[584] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 015D0FE5
.text C:\WINDOWS\Explorer.EXE[584] SHELL32.dll!SHFileOperationW 7CA6FDEE 5 Bytes JMP 01211102 C:\Program Files\Unlocker\UnlockerHook.dll
.text C:\WINDOWS\Explorer.EXE[584] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01460FEF
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00F4000A
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00F40F7E
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00F40069
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00F40058
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00F40FA5
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00F40FB6
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00F40F57
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00F4009F
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00F40F46
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00F400DF
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00F40F21
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00F40047
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00F4001B
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00F4008E
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00F40FDB
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00F4002C
.text C:\WINDOWS\system32\services.exe[852] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00F400BA
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00A40FC3
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00A40F79
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00A4000A
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00A40FD4
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00A40F8A
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00A40FEF
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00A40036
.text C:\WINDOWS\system32\services.exe[852] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00A40025
.text C:\WINDOWS\system32\services.exe[852] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A30F7F
.text C:\WINDOWS\system32\services.exe[852] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A30F90
.text C:\WINDOWS\system32\services.exe[852] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A30FBC
.text C:\WINDOWS\system32\services.exe[852] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A30FEF
.text C:\WINDOWS\system32\services.exe[852] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A30FAB
.text C:\WINDOWS\system32\services.exe[852] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A30000
.text C:\WINDOWS\system32\services.exe[852] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00A10FEF
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C7000A
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C70F80
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C70075
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C70F9B
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C70058
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C70047
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C700A1
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C70F59
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C700B2
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C70F23
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00C70F08
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00C70FB6
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00C7001B
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00C70090
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00C70036
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00C70FE5
.text C:\WINDOWS\system32\lsass.exe[864] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00C70F34
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00C60051
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00C6007D
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00C60040
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00C6001B
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00C60FC0
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00C60000
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00C6006C
.text C:\WINDOWS\system32\lsass.exe[864] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00C60FEF
.text C:\WINDOWS\system32\lsass.exe[864] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C50040
.text C:\WINDOWS\system32\lsass.exe[864] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C50FAB
.text C:\WINDOWS\system32\lsass.exe[864] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C50FC6
.text C:\WINDOWS\system32\lsass.exe[864] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C50000
.text C:\WINDOWS\system32\lsass.exe[864] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C50025
.text C:\WINDOWS\system32\lsass.exe[864] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C50FE3
.text C:\WINDOWS\system32\lsass.exe[864] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00C40000
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[996] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[996] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00A70000
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00A7007D
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00A70F92
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00A7006C
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00A70FB9
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00A70FCA
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00A70F6B
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00A700B3
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A70F3F
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A70F50
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00A70F2E
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00A7005B
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00A70011
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00A70098
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00A70FDB
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00A7002C
.text C:\WINDOWS\system32\svchost.exe[1032] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00A700C4
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00A60040
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00A60FC3
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00A6002F
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00A60014
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00A60080
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00A60FEF
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00A60FDE
.text C:\WINDOWS\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00A60065
.text C:\WINDOWS\system32\svchost.exe[1032] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A50050
.text C:\WINDOWS\system32\svchost.exe[1032] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A50FCF
.text C:\WINDOWS\system32\svchost.exe[1032] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A5002E
.text C:\WINDOWS\system32\svchost.exe[1032] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A50000
.text C:\WINDOWS\system32\svchost.exe[1032] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A5003F
.text C:\WINDOWS\system32\svchost.exe[1032] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A5001D
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 009E0000
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C50000
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C50F83
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C50082
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C50F9E
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C50FAF
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C50FDB
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C500BA
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C50F72
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C50F2B
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C50F3C
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00C500DF
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00C50FC0
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00C5001B
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00C50093
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00C5003D
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00C5002C
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00C50F4D
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00C40FEF
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00C40FA8
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00C40040
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00C4001B
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00C4005B
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00C40000
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00C40FC3
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00C40FDE
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C3004A
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C30025
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C3000A
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C30FEF
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C30FB5
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C30FC6
.text C:\WINDOWS\system32\svchost.exe[1080] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00A30FEF
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00A30F70
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00A3005B
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00A3004A
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00A30F8D
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00A30025
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00A3009B
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00A3008A
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A30F02
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A30F27
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00A30EF1
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00A30F9E
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00A30FD4
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00A30F5F
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00A30014
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00A30FC3
.text C:\WINDOWS\System32\svchost.exe[1332] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00A30F38
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00A20FCA
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00A20F94
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00A2001B
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00A2000A
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00A20047
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00A20FE5
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00A20036
.text C:\WINDOWS\System32\svchost.exe[1332] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00A20FB9
.text C:\WINDOWS\System32\svchost.exe[1332] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A10044
.text C:\WINDOWS\System32\svchost.exe[1332] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A10029
.text C:\WINDOWS\System32\svchost.exe[1332] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A10FD4
.text C:\WINDOWS\System32\svchost.exe[1332] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A1000C
.text C:\WINDOWS\System32\svchost.exe[1332] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A10FC3
.text C:\WINDOWS\System32\svchost.exe[1332] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A10FEF
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E60000
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E60073
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E60F7E
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E60062
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E60FAF
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E60040
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E60F3C
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E60F63
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E60EFF
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E60F10
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00E600B3
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00E60051
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00E60FDB
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00E6008E
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00E6001B
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00E60FCA
.text C:\Program Files\Messenger\msmsgs.exe[1408] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00E60F2B
.text C:\Program Files\Messenger\msmsgs.exe[1408] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E3005F
.text C:\Program Files\Messenger\msmsgs.exe[1408] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E30044
.text C:\Program Files\Messenger\msmsgs.exe[1408] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E30018
.text C:\Program Files\Messenger\msmsgs.exe[1408] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E30FEF
.text C:\Program Files\Messenger\msmsgs.exe[1408] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E30029
.text C:\Program Files\Messenger\msmsgs.exe[1408] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E30FDE
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00E4001B
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00E40062
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00E40FCA
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00E4000A
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00E40051
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00E40FEF
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00E40040
.text C:\Program Files\Messenger\msmsgs.exe[1408] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00E40FAF
.text C:\Program Files\Messenger\msmsgs.exe[1408] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00E20FEF
.text C:\Program Files\Messenger\msmsgs.exe[1408] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00E50000
.text C:\Program Files\Messenger\msmsgs.exe[1408] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00E50FE5
.text C:\Program Files\Messenger\msmsgs.exe[1408] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00E50FCA
.text C:\Program Files\Messenger\msmsgs.exe[1408] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00E50FB9
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00A00000
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00A00079
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00A00F7A
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00A00F8B
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00A00FB2
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00A00FDE
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00A00F58
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00A00094
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A00F33
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A000CC
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00A000DD
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00A00FC3
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00A00025
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00A00F69
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00A0004A
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00A00FEF
.text C:\WINDOWS\System32\svchost.exe[1556] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00A000BB
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 009E0051
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 009E0FAC
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 009E0040
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 009E0025
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 009E0073
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 009E000A
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 009E0FD1
.text C:\WINDOWS\System32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 009E0062
.text C:\WINDOWS\System32\svchost.exe[1556] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009D0FC7
.text C:\WINDOWS\System32\svchost.exe[1556] msvcrt.dll!system 77C293C7 5 Bytes JMP 009D005C
.text C:\WINDOWS\System32\svchost.exe[1556] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009D003A
.text C:\WINDOWS\System32\svchost.exe[1556] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009D000C
.text C:\WINDOWS\System32\svchost.exe[1556] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009D004B
.text C:\WINDOWS\System32\svchost.exe[1556] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009D0029
.text C:\WINDOWS\System32\svchost.exe[1556] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 009F0000
.text C:\WINDOWS\System32\svchost.exe[1556] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 009F001B
.text C:\WINDOWS\System32\svchost.exe[1556] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 009F0FDB
.text C:\WINDOWS\System32\svchost.exe[1556] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 009F002C
.text C:\WINDOWS\System32\svchost.exe[1556] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 009C0000
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01A20FEF
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01A20F52
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01A20F6D
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01A20047
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01A20F8A
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01A20036
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01A2009A
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 01A20089
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01A20F1C
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01A200BF
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 01A20F0B
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 01A20FAF
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 01A2000A
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 01A2006C
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 01A20025
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 01A20FD4
.text C:\WINDOWS\System32\svchost.exe[1724] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 01A20F41
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00A40FB2
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00A4004A
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00A40FC3
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00A40FD4
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00A40039
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00A40FE5
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00A40F97
.text C:\WINDOWS\System32\svchost.exe[1724] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00A4001E
.text C:\WINDOWS\System32\svchost.exe[1724] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A30042
.text C:\WINDOWS\System32\svchost.exe[1724] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A30FC1
.text C:\WINDOWS\System32\svchost.exe[1724] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A30FD2
.text C:\WINDOWS\System32\svchost.exe[1724] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A30000
.text C:\WINDOWS\System32\svchost.exe[1724] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A30031
.text C:\WINDOWS\System32\svchost.exe[1724] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A30FE3
.text C:\WINDOWS\System32\svchost.exe[1724] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00A20000
.text C:\WINDOWS\System32\svchost.exe[1724] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00A50FEF
.text C:\WINDOWS\System32\svchost.exe[1724] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00A50FD4
.text C:\WINDOWS\System32\svchost.exe[1724] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00A50000
.text C:\WINDOWS\System32\svchost.exe[1724] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00A50025
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00870000
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00870067
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00870F72
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00870F83
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00870F9E
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00870036
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00870F30
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00870078
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00870EFD
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00870F0E
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 008700B1
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00870FAF
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00870FE5
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00870F4D
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00870FD4
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00870025
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00870F1F
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00860FB9
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00860036
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00860FD4
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00860FE5
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00860F79
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00860000
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00860025
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00860FA8
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00850F92
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!system 77C293C7 5 Bytes JMP 00850027
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00850FD2
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00850FEF
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00850FC1
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0085000C
.text C:\WINDOWS\System32\svchost.exe[1812] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007B0000
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001B0000
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001B0F37
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001B002C
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001B0F5E
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001B0F6F
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001B0FA5
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001B0069
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001B0058
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001B008B
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001B0EFC
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 001B00A6
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 001B0F94
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 001B0FE5
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 001B0047
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 001B0FC0
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 001B0011
.text C:\WINDOWS\system32\wuauclt.exe[3068] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 001B007A
.text C:\WINDOWS\system32\wuauclt.exe[3068] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0029002E
.text C:\WINDOWS\system32\wuauclt.exe[3068] msvcrt.dll!system 77C293C7 5 Bytes JMP 00290FAD
.text C:\WINDOWS\system32\wuauclt.exe[3068] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00290FD2
.text C:\WINDOWS\system32\wuauclt.exe[3068] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00290FEF
.text C:\WINDOWS\system32\wuauclt.exe[3068] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0029001D
.text C:\WINDOWS\system32\wuauclt.exe[3068] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0029000C
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 002A0FA8
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 002A0036
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 002A0FB9
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 002A0FDE
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 002A0025
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 002A0FEF
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 002A000A
.text C:\WINDOWS\system32\wuauclt.exe[3068] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 002A0F83
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E40000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E40093
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E40078
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E40F9E
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E40FAF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E4005B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E400A4
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E40F5C
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E400D7
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E400C6
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00E400E8
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00E40FCA
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00E40025
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00E40F79
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00E40FE5
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00E40036
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00E400B5
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] MSVCRT.dll!_wsystem 77C2931E 5 Bytes JMP 00D90FC8
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] MSVCRT.dll!system 77C293C7 5 Bytes JMP 00D90049
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] MSVCRT.dll!_creat 77C2D40F 5 Bytes JMP 00D9001D
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] MSVCRT.dll!_open 77C2F566 5 Bytes JMP 00D90000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] MSVCRT.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D90038
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] MSVCRT.dll!_wopen 77C30055 5 Bytes JMP 00D90FE3
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00DA0000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00DA0F6F
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00DA0FAF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00DA0FCA
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00DA0F8A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00DA0FEF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00DA0036
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00DA001B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3208] WS2_32.DLL!socket 71AB3B91 5 Bytes JMP 00D80FE5
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F844406C] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8444018] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F84669AE] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F844406C] sptd.sys
IAT atapi.sys[ntoskrnl.exe!KeInitializeDpc] 823D7448
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F842DAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F842DC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F842DB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F842E748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F842E61E] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F844329A] sptd.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [63601740] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[1348] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 823D61E8
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\NetBT \Device\NetBT_Tcpip_{A7D9B8FC-079A-41D2-B567-BDDB50AE4953} 821D25F8
Device \Driver\usbuhci \Device\USBPDO-0 82211790
Device \Driver\usbuhci \Device\USBPDO-1 82211790
Device \Driver\usbuhci \Device\USBPDO-2 82211790
Device \Driver\usbehci \Device\USBPDO-3 8220C1E8
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\NetBT \Device\NetBT_Tcpip_{536FE13F-F252-499C-9BAB-DB89DDB7C4F6} 821D25F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8236B1E8
Device \Driver\Cdrom \Device\CdRom0 821E91E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 823D71E8
Device \Driver\atapi \Device\Ide\IdePort0 823D71E8
Device \Driver\atapi \Device\Ide\IdePort1 823D71E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 823D71E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 821D25F8
Device \Driver\NetBT \Device\NetbiosSmb 821D25F8
Device \Driver\PCI_NTPNP9686 \Device\0000004d sptd.sys
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\usbhub \Device\0000006a hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\0000006b hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-0 82211790
Device \Driver\usbuhci \Device\USBFDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\0000006c hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-1 82211790
Device \Driver\usbuhci \Device\USBFDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-2 82211790
Device \Driver\usbuhci \Device\USBFDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 82009790
Device \Driver\usbehci \Device\USBFDO-3 8220C1E8
Device \Driver\usbehci \Device\USBFDO-3 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\MRxSmb \Device\LanmanRedirector 82009790
Device \Driver\NetBT \Device\NetBT_Tcpip_{508CCC94-E128-4DF1-AE6C-0F87491505E0} 821D25F8
Device \Driver\Ftdisk \Device\FtControl 8236B1E8
Device \Driver\a1fsqa07 \Device\Scsi\a1fsqa071 821BC790
Device \FileSystem\Cdfs \Cdfs 821E2790
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA5 0xC9 0xED 0x42 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA5 0xC9 0xED 0x42 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
---- EOF - GMER 1.0.15 ----