GMER 1.0.15.15252 -
http://www.gmer.netRootkit scan 2009-11-24 18:58:45
Windows 5.1.2600 Service Pack 3
Running: c0k4b8eg.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pwtiyfog.sys
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[196] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\System32\svchost.exe[196] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\System32\svchost.exe[196] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\System32\svchost.exe[196] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\System32\svchost.exe[196] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\System32\svchost.exe[196] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\System32\svchost.exe[196] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!GetSysColor 7E418E78 5 Bytes JMP 004170D0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!GetSysColorBrush 7E418EAB 5 Bytes JMP 00417140 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!SetScrollInfo 7E419056 7 Bytes JMP 00416FC0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!GetScrollInfo 7E42DFE2 7 Bytes JMP 00416F10 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!ShowScrollBar 7E42F2F2 5 Bytes JMP 00417090 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!GetScrollPos 7E42F704 5 Bytes JMP 00416F50 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!SetScrollPos 7E42F750 5 Bytes JMP 00417000 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!GetScrollRange 7E42F787 5 Bytes JMP 00416F80 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!SetScrollRange 7E42F99B 5 Bytes JMP 00417040 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[284] USER32.dll!EnableScrollBar 7E468005 7 Bytes JMP 00416ED0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Documents and Settings\Administrator\temp\TeamViewer\Version4\TeamViewer.exe[348] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\System32\svchost.exe[456] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\System32\svchost.exe[456] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\System32\svchost.exe[456] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\System32\svchost.exe[456] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\System32\svchost.exe[456] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\System32\svchost.exe[456] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\System32\svchost.exe[456] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\System32\svchost.exe[456] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\CyberPower PowerPanel Persoanl Edition\ppped.exe[476] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\internet explorer\iexplore.exe[612] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\internet explorer\iexplore.exe[612] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\internet explorer\iexplore.exe[612] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 01694315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 017667BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 0188637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 018862AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 01886318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 0188617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 018861E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 018863DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 01886242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[612] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\internet explorer\iexplore.exe[612] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\internet explorer\iexplore.exe[612] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\internet explorer\iexplore.exe[612] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\internet explorer\iexplore.exe[612] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0044FCA9 C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (Sentrilock Card Utility/SentriLock LLC)
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe[624] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\winlogon.exe[708] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\winlogon.exe[708] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\winlogon.exe[708] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\winlogon.exe[708] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\winlogon.exe[708] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\winlogon.exe[708] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\winlogon.exe[708] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\winlogon.exe[708] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\services.exe[760] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\services.exe[760] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\services.exe[760] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\services.exe[760] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\services.exe[760] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\services.exe[760] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\services.exe[760] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\services.exe[760] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\lsass.exe[772] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\lsass.exe[772] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\lsass.exe[772] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\lsass.exe[772] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\lsass.exe[772] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\lsass.exe[772] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\lsass.exe[772] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\lsass.exe[772] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[852] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\Ati2evxx.exe[964] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\Ati2evxx.exe[964] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\Ati2evxx.exe[964] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\Ati2evxx.exe[964] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\Ati2evxx.exe[964] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\Ati2evxx.exe[964] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\Ati2evxx.exe[964] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[984] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[984] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[984] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[984] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[984] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[1024] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[1068] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[1068] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[1068] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[1068] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[1068] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[1068] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\System32\svchost.exe[1168] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\System32\svchost.exe[1168] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\System32\svchost.exe[1168] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\System32\svchost.exe[1168] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\System32\svchost.exe[1168] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\System32\svchost.exe[1168] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\System32\svchost.exe[1168] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\SearchIndexer.exe[1360] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[1376] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[1376] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[1376] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[1376] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[1376] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\spoolsv.exe[1580] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\spoolsv.exe[1580] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\spoolsv.exe[1580] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\spoolsv.exe[1580] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\spoolsv.exe[1580] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\spoolsv.exe[1580] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\spoolsv.exe[1580] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\spoolsv.exe[1580] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\System32\SCardSvr.exe[1644] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\System32\SCardSvr.exe[1644] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\System32\SCardSvr.exe[1644] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\System32\SCardSvr.exe[1644] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\System32\SCardSvr.exe[1644] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\System32\SCardSvr.exe[1644] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\System32\SCardSvr.exe[1644] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\System32\SCardSvr.exe[1644] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[1716] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[1716] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[1716] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[1716] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[1716] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[1716] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[1716] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[1716] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C