GMER 1.0.12.12086 -
http://www.gmer.net
Rootkit scan 2007-04-05 01:08:11
Windows 5.1.2600 Service Pack 1
---- System - GMER 1.0.12 ----
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwClose
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateKey
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateProcess
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateProcessEx
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateThread
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwDeleteFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwDeleteKey
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwDeleteValueKey
SSDT \SystemRoot\system32\drivers\khips.sys ZwLoadDriver
SSDT \SystemRoot\system32\drivers\khips.sys ZwMapViewOfSection
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwOpenFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwResumeThread
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwSetInformationFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwSetValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwWriteFile
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!KeInitializeInterrupt + B67 804DA23C 1 Byte [ 06 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 170 805025EC 4 Bytes [ 80, DF, F9, F4 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1A0 8050261C 4 Bytes [ 52, D5, F9, F4 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1B0 8050262C 4 Bytes [ 82, 98, F9, F4 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1C8 80502644 8 Bytes [ 1A, CA, F9, F4, 10, C9, F9, ... ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1E0 8050265C 4 Bytes [ 2A, CF, F9, F4 ]
.text ...
PAGENDSM NDIS.sys!NdisMIndicateStatus F9D4587D 6 Bytes JMP F4F91C5E \SystemRoot\system32\drivers\fwdrv.sys
.text ntdll.dll!NtClose 77F658AA 5 Bytes JMP 720342BA
.text ntdll.dll!NtCreateProcess 77F659F4 5 Bytes JMP 72034445
.text ntdll.dll!NtCreateProcessEx 77F65A03 5 Bytes JMP 72034329
.text ntdll.dll!NtCreateSection 77F65A21 5 Bytes JMP 720342D8
---- User code sections - GMER 1.0.12 ----
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\ctfmon.exe[308] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\ctfmon.exe[308] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\ctfmon.exe[308] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\explorer.exe[460] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\explorer.exe[460] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\explorer.exe[460] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\explorer.exe[460] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\explorer.exe[460] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\explorer.exe[460] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\explorer.exe[460] WININET.dll!InternetConnectA 76195DE6 5 Bytes JMP 00070F54
.text C:\WINDOWS\explorer.exe[460] WININET.dll!InternetConnectW 7619AA8A 5 Bytes JMP 00070FE0
.text C:\WINDOWS\explorer.exe[460] WININET.dll!InternetOpenA 761A017D 5 Bytes JMP 00070D24
.text C:\WINDOWS\explorer.exe[460] WININET.dll!InternetOpenW 761A08D4 5 Bytes JMP 00070DB0
.text C:\WINDOWS\explorer.exe[460] WININET.dll!InternetOpenUrlA 761A1DEF 5 Bytes JMP 00070E3C
.text C:\WINDOWS\explorer.exe[460] WININET.dll!InternetOpenUrlW 761D0D67 5 Bytes JMP 00070EC8
.text C:\WINDOWS\system32\csrss.exe[572] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00160720
.text C:\WINDOWS\system32\csrss.exe[572] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001607AC
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00160090
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00160694
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001602C0
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00160234
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!WinExec 77E4FD35 5 Bytes JMP 00160464
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0016034C
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0016011C
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00160004
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001604F0
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!CreateThread 77E5BE53 5 Bytes JMP 0016057C
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001601A8
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001603D8
.text C:\WINDOWS\system32\csrss.exe[572] KERNEL32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00160608
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\winlogon.exe[596] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\winlogon.exe[596] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\winlogon.exe[596] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\winlogon.exe[596] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\winlogon.exe[596] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\winlogon.exe[596] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\services.exe[640] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\services.exe[640] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\services.exe[640] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\services.exe[640] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\services.exe[640] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\services.exe[640] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\lsass.exe[652] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\lsass.exe[652] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\lsass.exe[652] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\lsass.exe[652] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\lsass.exe[652] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\lsass.exe[652] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\svchost.exe[828] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\svchost.exe[828] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\svchost.exe[828] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\svchost.exe[828] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\svchost.exe[828] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\svchost.exe[880] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\svchost.exe[880] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\svchost.exe[880] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\svchost.exe[880] WININET.dll!InternetConnectA 76195DE6 5 Bytes JMP 00070F54
.text C:\WINDOWS\system32\svchost.exe[880] WININET.dll!InternetConnectW 7619AA8A 5 Bytes JMP 00070FE0
.text C:\WINDOWS\system32\svchost.exe[880] WININET.dll!InternetOpenA 761A017D 5 Bytes JMP 00070D24
.text C:\WINDOWS\system32\svchost.exe[880] WININET.dll!InternetOpenW 761A08D4 5 Bytes JMP 00070DB0
.text C:\WINDOWS\system32\svchost.exe[880] WININET.dll!InternetOpenUrlA 761A1DEF 5 Bytes JMP 00070E3C
.text C:\WINDOWS\system32\svchost.exe[880] WININET.dll!InternetOpenUrlW 761D0D67 5 Bytes JMP 00070EC8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] WS2_32.dll!socket 719F3C22 5 Bytes JMP 001308C4
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00130950
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[960] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00130838
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\svchost.exe[1044] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\svchost.exe[1044] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\svchost.exe[1044] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\svchost.exe[1044] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\svchost.exe[1044] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\svchost.exe[1044] WININET.dll!InternetConnectA 76195DE6 5 Bytes JMP 00070F54
.text C:\WINDOWS\system32\svchost.exe[1044] WININET.dll!InternetConnectW 7619AA8A 5 Bytes JMP 00070FE0
.text C:\WINDOWS\system32\svchost.exe[1044] WININET.dll!InternetOpenA 761A017D 5 Bytes JMP 00070D24
.text C:\WINDOWS\system32\svchost.exe[1044] WININET.dll!InternetOpenW 761A08D4 5 Bytes JMP 00070DB0
.text C:\WINDOWS\system32\svchost.exe[1044] WININET.dll!InternetOpenUrlA 761A1DEF 5 Bytes JMP 00070E3C
.text C:\WINDOWS\system32\svchost.exe[1044] WININET.dll!InternetOpenUrlW 761D0D67 5 Bytes JMP 00070EC8
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\spoolsv.exe[1208] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\spoolsv.exe[1208] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\spoolsv.exe[1208] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\spoolsv.exe[1208] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\spoolsv.exe[1208] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\spoolsv.exe[1208] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00070090
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00070694
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000702C0
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00070234
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00070464
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0007034C
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0007011C
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00070004
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000704F0
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0007057C
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000701A8
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000703D8
.text C:\WINDOWS\system32\alg.exe[1312] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00070608
.text C:\WINDOWS\system32\alg.exe[1312] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00070720
.text C:\WINDOWS\system32\alg.exe[1312] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000707AC
.text C:\WINDOWS\system32\alg.exe[1312] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000708C4
.text C:\WINDOWS\system32\alg.exe[1312] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00070950
.text C:\WINDOWS\system32\alg.exe[1312] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00070838
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1324] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\WINDOWS\system32\Crypserv.exe[1352] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\WINDOWS\system32\Crypserv.exe[1352] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\WINDOWS\system32\Crypserv.exe[1352] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00030090
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00030694
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 000302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00030234
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00030464
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0003034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0003011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00030004
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 000304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0003057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 000301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 000303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00030608
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00030720
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 000307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WS2_32.dll!socket 719F3C22 5 Bytes JMP 000308C4
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00030950
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00030838
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WININET.dll!InternetConnectA 76195DE6 5 Bytes JMP 00030F54
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WININET.dll!InternetConnectW 7619AA8A 5 Bytes JMP 00030FE0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WININET.dll!InternetOpenA 761A017D 5 Bytes JMP 00030D24
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WININET.dll!InternetOpenW 761A08D4 5 Bytes JMP 00030DB0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WININET.dll!InternetOpenUrlA 761A1DEF 5 Bytes JMP 00030E3C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[1384] WININET.dll!InternetOpenUrlW 761D0D67 5 Bytes JMP 00030EC8
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WS2_32.dll!socket 719F3C22 5 Bytes JMP 001308C4
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WS2_32.dll!connect 719F3E5D 5 Bytes JMP 00130950
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WS2_32.dll!bind 719F3ECE 5 Bytes JMP 00130838
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WININET.dll!InternetConnectA 76195DE6 5 Bytes JMP 00130F54
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WININET.dll!InternetConnectW 7619AA8A 5 Bytes JMP 00130FE0
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WININET.dll!InternetOpenA 761A017D 5 Bytes JMP 00130D24
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WININET.dll!InternetOpenW 761A08D4 5 Bytes JMP 00130DB0
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WININET.dll!InternetOpenUrlA 761A1DEF 5 Bytes JMP 00130E3C
.text C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe[1416] WININET.dll!InternetOpenUrlW 761D0D67 5 Bytes JMP 00130EC8
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe[1424] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\Program Files\Winamp\winampa.exe[1512] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\Program Files\Winamp\winampa.exe[1512] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\Program Files\Winamp\winampa.exe[1512] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE[1560] USER32.dll!SetWindowsHookExW 77D2506A 5 Bytes JMP 001307AC
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!VirtualProtect 77E4169E 5 Bytes JMP 00130090
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!WriteProcessMemory 77E41A94 5 Bytes JMP 00130694
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!CreateProcessW 77E41B8E 5 Bytes JMP 001302C0
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!CreateProcessA 77E41BBC 5 Bytes JMP 00130234
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!WinExec 77E4FD35 5 Bytes JMP 00130464
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!CreateProcessInternalA 77E53306 5 Bytes JMP 0013034C
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!VirtualAllocEx 77E5AC24 5 Bytes JMP 0013011C
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!VirtualAlloc 77E5AC72 5 Bytes JMP 00130004
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!CreateRemoteThread 77E5BC9F 5 Bytes JMP 001304F0
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!CreateThread 77E5BE53 5 Bytes JMP 0013057C
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!VirtualProtectEx 77E5D258 5 Bytes JMP 001301A8
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!CreateProcessInternalW 77E6033A 5 Bytes JMP 001303D8
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] kernel32.dll!SetThreadContext 77E7391A 5 Bytes JMP 00130608
.text C:\WINDOWS\system32\LVCOMSX.EXE[1572] USER32.dll!SetWindowsHookExA 77D25006 5 Bytes JMP 00130720
.text C:\WINDOW