This thread's last reply is from October 5, 2010, 10:32 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
I have a laptop that is infected with several sorts of malware. I have run several programs on it before I came to this wonderful site. I have run Avira, Superantispyware, malwarebytes, and hostxperts.exe. The computer is very slow. It will connect to google.com but will not go to any antivirus sites. It has also seemed to stop going to regular sites too i.e. local news etc. I attempted to run hostxperts.exe to fix the host file issue but it would not allow me to write in C:Windows/system32/drivers/etc . So I looked on the internet and did it manually. And I don't think I did a very good job. initially there were many many lines of wierd websites but now it is just local host.
my hijack this log follows I hope you can help. Please let me know if I need to give you any other information.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:08:45 AM, on 9/30/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\cmd.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100911014004.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe -update activex
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... -
res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10482 bytes
Here are the logs you requested.
DDS (Ver_10-03-17.01) - NTFSx86
Run by [redacted] at 2:40:30.42 on Sun 10/03/2010
Internet Explorer: 8.0.6001.18943
Microsoft® Windows Vista Home Basic 6.0.6001.1.1252.1.1033.18.3573.2474 [GMT -5:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\aestsrv.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\mvaliquette\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://www.google.com/ig/dell?hl=en&cli ... bd=5080617
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL =
hxxp://www.google.com/ig/dell?hl=en&cli ... bd=5080617
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100930224523.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
hxxp://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-9-29 64288]
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-9-11 386712]
R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2010-9-11 64304]
R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-9-11 164808]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-6-16 73728]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-9-29 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-9-29 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-9-29 60936]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-11 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-11 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-11 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-9-11 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-9-11 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-9-11 141792]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-9-12 1153368]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-9-11 55840]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-16 111616]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-9-11 152992]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-9-11 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-9-11 312904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1356952]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-9-11 84264]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-6-16 30192]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-2 135664]
=============== Created Last 30 ================
2010-10-02 06:25:51 0 d-----w- C:\MGADiagToolOutput
2010-09-30 03:11:23 0 d-----w- c:\users\mvaliq~1\appdata\roaming\Avira
2010-09-30 03:06:09 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-30 03:06:07 0 d-----w- c:\programdata\Avira
2010-09-30 03:06:07 0 d-----w- c:\program files\Avira
2010-09-29 22:23:29 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-09-29 19:44:43 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-09-29 17:28:25 0 d-----w- c:\program files\Trend Micro
2010-09-29 17:22:02 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-09-29 17:21:52 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-29 17:17:35 0 d-----w- c:\programdata\Lavasoft
2010-09-29 17:17:35 0 d-----w- c:\program files\Lavasoft
2010-09-29 16:59:30 0 dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-29 16:11:27 0 d-----w- c:\users\mvaliq~1\appdata\roaming\SUPERAntiSpyware.com
2010-09-29 16:11:27 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-09-29 16:11:23 0 d-----w- c:\program files\SUPERAntiSpyware
2010-09-29 14:29:06 0 d-----w- c:\users\mvaliq~1\appdata\roaming\Malwarebytes
2010-09-29 14:28:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-29 14:28:57 0 d-----w- c:\programdata\Malwarebytes
2010-09-29 14:28:55 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-29 14:28:55 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-12 17:18:04 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-12 17:18:04 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-09-11 06:40:01 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-09-11 06:39:49 84264 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-09-11 06:39:49 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2010-09-11 06:39:49 386712 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-09-11 06:39:49 164808 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2010-09-11 06:39:48 95600 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-09-11 06:39:48 55840 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-09-11 06:39:48 52104 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-09-11 06:39:48 312904 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-09-11 06:39:48 152992 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
==================== Find3M ====================
2010-09-11 06:40:56 51200 ----a-w- c:\windows\inf\infpub.dat
2010-09-11 06:40:56 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-09-11 06:40:55 86016 ----a-w- c:\windows\inf\infstor.dat
2008-06-27 22:20:26 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:57:01 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:39:34 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39:34 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:39:34 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39:34 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 2:41:58.23 ===============
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6001 (Service Pack 1)
Number of processors #1
==============================================
>Drivers
==============================================
0x8FA0B000 C:\Windows\system32\DRIVERS\igdkmd32.sys 6606848 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x82240000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)
0x82240000 PnpManager 3903488 bytes
0x82240000 RAW 3903488 bytes
0x82240000 WMIxWDM 3903488 bytes
0x974C0000 Win32k 2105344 bytes
0x974C0000 C:\Windows\System32\win32k.sys 2105344 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8BA09000 C:\Windows\System32\Drivers\Ntfs.sys 1110016 bytes (Microsoft Corporation, NT File System Driver)
0x82A80000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x90603000 C:\Windows\system32\DRIVERS\HSX_DPV.sys 1060864 bytes (Conexant Systems, Inc., HSF_DP driver)
0x8F8ED000 C:\Windows\system32\DRIVERS\bcmwl6.sys 1056768 bytes (Broadcom Corp., Broadcom 802.11 Network Adapter wireless driver)
0x908D0000 C:\Windows\System32\drivers\tcpip.sys 954368 bytes (Microsoft Corporation, TCP/IP Driver)
0x804C5000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)
0xAE601000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x8F800000 C:\Windows\System32\Drivers\dump_iaStor.sys 815104 bytes
0x82806000 C:\Windows\system32\drivers\iastor.sys 815104 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0x90706000 C:\Windows\system32\DRIVERS\HSX_CNXT.sys 737280 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0xA9439000 C:\Windows\system32\drivers\spsys.sys 716800 bytes (Microsoft Corporation, security processor)
0x90058000 C:\Windows\System32\drivers\dxgkrnl.sys 651264 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8060D000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x82A0F000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xA953F000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8040B000 C:\Windows\system32\mcupdate_GenuineIntel.dll 393216 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x82935000 C:\Windows\system32\drivers\mfehidk.sys 380928 bytes (McAfee, Inc., McAfee Link Driver)
0x90805000 C:\Windows\system32\drivers\stwrt.sys 348160 bytes (IDT, Inc., NDHF)
0x829AA000 C:\Windows\system32\DRIVERS\rixdptsk.sys 331776 bytes (REDC, RICOH XD SM Driver)
0xADCBE000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x9016E000 C:\Windows\system32\DRIVERS\yk60x86.sys 311296 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.)
0x90B9C000 C:\Windows\system32\drivers\mfefirek.sys 307200 bytes (McAfee, Inc., McAfee Core Firewall Engine Driver)
0x8073F000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x90A3E000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x80696000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)
0x80484000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x90409000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x9010F000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x9056A000 C:\Windows\system32\DRIVERS\HSXHWAZL.sys 249856 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0x90AF9000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x82BB6000 C:\Windows\system32\drivers\NETIO.SYS 237568 bytes (Microsoft Corporation, Network I/O Subsystem)
0xADC46000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8BB18000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x90525000 C:\Windows\system32\DRIVERS\usbhub.sys 212992 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x8220D000 ACPI_HAL 208896 bytes
0x8220D000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x828F3000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x90A0C000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x805A5000 C:\Windows\system32\DRIVERS\msiscsi.sys 188416 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x905A7000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x807B5000 C:\Windows\system32\DRIVERS\Apfiltr.sys 180224 bytes (Alps Electric Co., Ltd., Alps Touch Pad Driver)
0x82B8B000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x904E4000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0xA94F8000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0xADD28000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)
0x8BB68000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x909D4000 C:\Windows\system32\drivers\mfewfpk.sys 159744 bytes (McAfee, Inc., Anti-Virus Mini-Firewall Driver)
0x806ED000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xADC97000 C:\Windows\System32\DRIVERS\srv2.sys 159744 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x905D4000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x90B78000 C:\Windows\system32\drivers\mfeavfk.sys 147456 bytes (McAfee, Inc., Anti-Virus File System Filter Driver)
0x90477000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x90B56000 C:\Windows\system32\DRIVERS\avipbb.sys 139264 bytes (Avira GmbH, Avira Driver for Security Enhancement)
0x90AD1000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS)
0x8BBA0000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0x907C7000 C:\Windows\system32\drivers\IntcHdmi.sys 135168 bytes (Intel(R) Corporation, Intel(R) High Definition Audio HDMI)
0x9087D000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0xADC07000 C:\Windows\system32\drivers\mrxdav.sys 131072 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xADC27000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x828D5000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0xA95AC000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x909B9000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0xA9409000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0x901D8000 C:\Windows\system32\DRIVERS\sdbus.sys 106496 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0xA95C9000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x807E1000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xADC7F000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x90B3F000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x90455000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xAE74E000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xAE72D000 C:\Windows\system32\drivers\mfeapfk.sys 90112 bytes (McAfee, Inc., Access Protection Filter Driver)
0x90A86000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x907E8000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0xA9424000 C:\Windows\system32\DRIVERS\avgntflt.sys 86016 bytes (Avira GmbH, Avira Minifilter Driver)
0xA95E2000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x904BD000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0xAE778000 C:\Windows\system32\DRIVERS\WUDFRd.sys 86016 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector)
0x904A9000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x8BBD7000 C:\Windows\system32\DRIVERS\rimsptsk.sys 81920 bytes (REDC, RICOH MS Driver)
0x805D3000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8BBEB000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)
0xA952C000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x90AB8000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x9015C000 C:\Windows\system32\DRIVERS\HDAudBus.sys 73728 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0xAE764000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 73728 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
0xAE78D000 C:\Windows\system32\DRIVERS\WUDFPf.sys 73728 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0x8BB8F000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x90559000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x8046B000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x82925000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0xA94E8000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x807A5000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x901BA000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0x904D2000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x8F8DE000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x82992000 C:\Windows\system32\DRIVERS\Lbd.sys 61440 bytes (Lavasoft AB, Boot Driver)
0x82A00000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x8BB59000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x80714000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x9049A000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x8F9EF000 C:\Windows\system32\DRIVERS\rimmptsk.sys 61440 bytes (REDC, RICOH SD Driver)
0x9014D000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x80730000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x901CA000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0x97700000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x90A9C000 C:\Windows\system32\DRIVERS\mfenlfk.sys 57344 bytes (McAfee, Inc., McAfee NDIS Light Filter Driver)
0x90AAA000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x908B9000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x80790000 C:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x90BE7000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x907BA000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x90518000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x900F7000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver)
0x80689000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0xAE721000 C:\Windows\system32\drivers\cfwids.sys 49152 bytes (McAfee, Inc., McAfee Personal Firewall IDS Plugin)
0xAE6E9000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x90871000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8FA00000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)
0xAE743000 C:\Windows\system32\drivers\mfebopk.sys 45056 bytes (McAfee, Inc., Buffer Overflow Protection Driver)
0x901F2000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)
0x908AE000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x9046C000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x9044A000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x8F8CA000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x90104000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x80726000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x90BF4000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x9050E000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0xA9522000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x90B35000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0xAE6DF000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x8BBC1000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x9085A000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0xAE79F000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x829A1000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0x908C7000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x976E0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8F8D5000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x82BF4000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x806DC000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x828CD000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x8047C000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x8837A000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x806E5000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x9089E000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x908A6000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8BB51000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0xAE6F5000 C:\Windows\system32\DRIVERS\xaudio.sys 32768 bytes (Conexant Systems, Inc., Modem Audio Device Driver)
0x9086A000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x80789000 C:\Windows\system32\DRIVERS\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x90863000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8079E000 C:\Windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
0x8BA00000 C:\Windows\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0x90AF3000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS)
0x90ACB000 C:\Windows\system32\DRIVERS\ssmdrv.sys 24576 bytes (Avira GmbH, AVIRA SnapShot Driver)
0x82BF0000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0xADD24000 C:\Windows\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface x86 Driver)
0x80723000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x904E2000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xAE776000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
!!!!!!!!!!!Hidden driver: 0x87561999 ?_empty_? 1639 bytes
==============================================
>Stealth
==============================================
0x82806000 WARNING: suspicious driver modification [iastor.sys::0x87561999]
0x01B20000 Hidden Image-->SupportSoft.Agent.Sprocket.dll [ EPROCESS 0x88D40020 ] PID: 3580, 28672 bytes
0x05BA0000 Hidden Image-->WLTRAY.EXE [ EPROCESS 0x87344190 ] PID: 1800, 3821568 bytes
0x01AF0000 Hidden Image-->SupportSoft.Agent.Sprocket.SupportMessage.dll [ EPROCESS 0x88D40020 ] PID: 3580, 45056 bytes
0x01CC0000 Hidden Image-->msvcm80.dll [ EPROCESS 0x87344190 ] PID: 1800, 507904 bytes
0x04650000 Hidden Image-->msvcm80.dll [ EPROCESS 0x89234B88 ] PID: 3404, 507904 bytes
0x01320000 Hidden Image-->bcmwlrmt.dll [ EPROCESS 0x87344190 ] PID: 1800, 77824 bytes
0x02370000 Hidden Image-->bcmwlrmt.dll [ EPROCESS 0x89234B88 ] PID: 3404, 77824 bytes
0x016C0000 Hidden Image-->sprtmessage.dll [ EPROCESS 0x88D40020 ] PID: 3580, 77824 bytes
==============================================
>Files
==============================================
!-->[Hidden] C:\ProgramData\McAfee\VirusScan\Quarantine\7daa33ca1e20.bup
!-->[Hidden] C:\ProgramData\McAfee\VirusScan\Quarantine\7daa33cad90.bup
!-->[Hidden] C:\ProgramData\McAfee\VirusScan\Quarantine\7daa33cb2da0.bup
!-->[Hidden] C:\ProgramData\McAfee\VirusScan\Quarantine\7daa33cb3b50.bup
!-->[Hidden] C:\ProgramData\McAfee\VirusScan\Quarantine\7daa33cbd0.bup
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Microsoft\Windows\WER\ReportQueue\store.lock
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Temp\~DF2068.tmp::$DATA
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Temp\~DF37A4.tmp::$DATA
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Temp\~DF4D41.tmp::$DATA
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Temp\~DF5360.tmp::$DATA
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Temp\~DF9811.tmp::$DATA
!-->[Hidden] C:\Users\mvaliquette\AppData\Local\Temp\~DF9830.tmp::$DATA
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[redacted][2].txt::$DATA
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[redacted][1].txt::$DATA
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[1].txt::$DATA
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@questionmarket[2].txt::$DATA
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@serving-sys[2].txt::$DATA
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x000B4EEA, Type: Inline - RelativeJump 0x822F4EEA-->822F4EF1 [ntkrnlpa.exe]
ntkrnlpa.exe-->NtMapViewOfSection, Type: Inline - RelativeJump 0x8246480E-->8296806C [mfehidk.sys]
ntkrnlpa.exe-->NtTerminateProcess, Type: Inline - RelativeJump 0x82422FBC-->82968096 [mfehidk.sys]
ntkrnlpa.exe-->NtUnmapViewOfSection, Type: Inline - RelativeJump 0x82464E65-->82968082 [mfehidk.sys]
ntkrnlpa.exe-->NtYieldExecution, Type: Inline - RelativeJump 0x822671C0-->82968058 [mfehidk.sys]
[1040]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1040]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1040]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1040]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1040]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1040]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1040]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1040]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1040]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1040]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1040]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1172]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1172]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1172]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1172]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1172]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1172]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1172]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1172]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1172]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1172]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1248]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1248]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1248]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1248]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1248]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1248]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1248]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1248]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1248]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1248]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1284]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1284]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1284]svchost.exe-->mswsock.dll+0x000024B9, Type: Inline - RelativeJump 0x757424B9-->00000000 [unknown_code_page]
[1284]svchost.exe-->mswsock.dll+0x00005604, Type: Inline - RelativeJump 0x75745604-->00000000 [unknown_code_page]
[1284]svchost.exe-->mswsock.dll+0x000057C5, Type: Inline - RelativeJump 0x757457C5-->00000000 [unknown_code_page]
[1284]svchost.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77C099E8-->00000000 [unknown_code_page]
[1284]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1284]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1284]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1284]svchost.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77C092A8-->00000000 [unknown_code_page]
[1284]svchost.exe-->user32.dll-->GetCursorPos, Type: Inline - RelativeJump 0x77D20F5E-->00000000 [unknown_code_page]
[1284]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1284]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1284]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1284]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1284]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1400]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1400]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1400]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1400]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1400]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1400]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1400]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1400]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1400]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1400]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1432]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1432]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1432]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1432]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1432]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1432]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1432]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1432]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1432]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1432]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1496]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1496]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1496]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1496]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1496]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1496]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1496]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1496]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1496]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1496]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1544]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1544]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1544]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1544]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1544]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1544]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1544]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1544]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1544]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[1620]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[1620]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[1620]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[1620]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[1620]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[1620]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[1620]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[1620]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[1620]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[1620]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[2012]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[2012]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[2012]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[2012]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[2012]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[2012]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[2012]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[2012]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[2012]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[2012]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[2340]McSvHost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [McProxy.dll]
[2340]McSvHost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [McProxy.dll]
[3104]explorer.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[3104]explorer.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[3104]explorer.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[3104]explorer.exe-->mswsock.dll+0x000024B9, Type: Inline - RelativeJump 0x757424B9-->00000000 [unknown_code_page]
[3104]explorer.exe-->mswsock.dll+0x00005604, Type: Inline - RelativeJump 0x75745604-->00000000 [unknown_code_page]
[3104]explorer.exe-->mswsock.dll+0x000057C5, Type: Inline - RelativeJump 0x757457C5-->00000000 [unknown_code_page]
[3104]explorer.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77C099E8-->00000000 [unknown_code_page]
[3104]explorer.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[3104]explorer.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[3104]explorer.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[3104]explorer.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77C092A8-->00000000 [unknown_code_page]
[3104]explorer.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[3104]explorer.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[3104]explorer.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[3104]explorer.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[3104]explorer.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[588]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[588]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[588]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[588]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[588]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[588]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[588]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[588]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[588]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[588]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[764]services.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[764]services.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[764]services.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[764]services.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[764]services.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[764]services.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[764]services.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[764]services.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[764]services.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[764]services.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[780]lsass.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[780]lsass.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[780]lsass.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[780]lsass.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[780]lsass.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[780]lsass.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[780]lsass.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[780]lsass.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[780]lsass.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[780]lsass.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x7759B8AE-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x7759B5E7-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x775ABCE1-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x775AB83D-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x775A0BF5-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x775AD4E8-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x775BF09D-->00000000 [unknown_code_page]
[952]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x775B3CB0-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7708CF71-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7708CC4E-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x770D430E-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x77045C44-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x77070284-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x77041C36-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x77041C01-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7708B8B6-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x770419C9-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x77041929-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x77069491-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x77069469-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x770630C3-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7706361F-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x77041DD1-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x77068D7E-->00000000 [unknown_code_page]
[952]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x770D54FF-->00000000 [unknown_code_page]
[952]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x77C08008-->00000000 [unknown_code_page]
[952]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x77C080C8-->00000000 [unknown_code_page]
[952]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C08968-->00000000 [unknown_code_page]
[952]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x7628D690-->00000000 [unknown_code_page]
[952]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x7628F3A4-->00000000 [unknown_code_page]
[952]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x762D6DDF-->00000000 [unknown_code_page]
[952]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x7628DB09-->00000000 [unknown_code_page]
[952]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x777736D1-->00000000 [unknown_code_page]