GMER (pt1) :
GMER 1.0.15.15570 -
http://www.gmer.net
Rootkit scan 2011-03-27 21:33:02
Windows 5.1.2600 Service Pack 3
Running: w1l3bdcc.exe; Driver: C:\DOCUME~1\Tatiana\LOCALS~1\Temp\pxtdrpoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwClose [0xB0A31CF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateKey [0xB0A31BAC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDeleteKey [0xB0A32160]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDeleteValueKey [0xB0A3208A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDuplicateObject [0xB0A31782]
SSDT spwc.sys ZwEnumerateKey [0xB9EC5CA4]
SSDT spwc.sys ZwEnumerateValueKey [0xB9EC6032]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenKey [0xB0A31C86]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenProcess [0xB0A316C2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenThread [0xB0A31726]
SSDT spwc.sys ZwQueryKey [0xB9EC610A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwQueryValueKey [0xB0A31DA6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xB0A3222E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRestoreKey [0xB0A31D66]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwSetValueKey [0xB0A31EE6]
INT 0x62 ? 8A620BF8
INT 0x63 ? 8A691BF8
INT 0x84 ? 8A690BF8
INT 0x94 ? 8A690BF8
INT 0xA4 ? 8A690BF8
INT 0xB4 ? 8A690BF8
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xB0A3EBAE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0xB0A3E9D2]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0xB0A3EB0C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntkrnlpa.exe!ZwLoadDriver 80584160 7 Bytes JMP B0A3EB10 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB3C8 7 Bytes JMP B0A3E9D6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC556 5 Bytes JMP B0A3A5D4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2FDA 5 Bytes JMP B0A3BFFA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D117A 7 Bytes JMP B0A3EBB2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? spwc.sys Le fichier spécifié est introuvable. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB84B4360, 0x307AC7, 0xE8000020]
.text USBPORT.SYS!DllUnload B843F8AC 5 Bytes JMP 8A6901D8
? C:\DOCUME~1\Tatiana\LOCALS~1\Temp\aswMBR.sys Le fichier spécifié est introuvable. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BB6ADE3
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 00CF000A
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BB766A5
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BB84DEB
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BB6AB2D
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BB7675B
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 00D0000A
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 00CE000C
.text C:\WINDOWS\Explorer.EXE[300] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BB84A78
.text C:\WINDOWS\Explorer.EXE[300] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BB7D9C5
.text C:\WINDOWS\Explorer.EXE[300] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BB6CA54
.text C:\WINDOWS\Explorer.EXE[300] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BB720ED
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\Program Files\Digital Line Detect\DLG.exe[352] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\Program Files\Digital Line Detect\DLG.exe[352] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\Program Files\Digital Line Detect\DLG.exe[352] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\Program Files\Digital Line Detect\DLG.exe[352] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\svchost.exe[512] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\svchost.exe[512] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\svchost.exe[512] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\svchost.exe[512] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\system32\svchost.exe[512] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\spoolsv.exe[848] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\spoolsv.exe[848] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\spoolsv.exe[848] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\spoolsv.exe[848] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\spoolsv.exe[848] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\spoolsv.exe[848] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\spoolsv.exe[848] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\spoolsv.exe[848] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\spoolsv.exe[848] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\spoolsv.exe[848] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\system32\spoolsv.exe[848] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\winlogon.exe[892] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\winlogon.exe[892] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\winlogon.exe[892] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\winlogon.exe[892] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\winlogon.exe[892] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\winlogon.exe[892] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\winlogon.exe[892] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\winlogon.exe[892] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\system32\winlogon.exe[892] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\winlogon.exe[892] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\winlogon.exe[892] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\lsass.exe[952] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\lsass.exe[952] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\lsass.exe[952] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\lsass.exe[952] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\lsass.exe[952] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\lsass.exe[952] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\lsass.exe[952] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\lsass.exe[952] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\lsass.exe[952] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\lsass.exe[952] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\lsass.exe[952] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\svchost.exe[1132] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\svchost.exe[1132] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\svchost.exe[1132] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\ehome\ehtray.exe[1192] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\ehome\ehtray.exe[1192] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\ehome\ehtray.exe[1192] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\ehome\ehtray.exe[1192] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\ehome\ehtray.exe[1192] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\ehome\ehtray.exe[1192] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\ehome\ehtray.exe[1192] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\ehome\ehtray.exe[1192] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\ehome\ehtray.exe[1192] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\ehome\ehtray.exe[1192] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\ehome\ehtray.exe[1192] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\svchost.exe[1212] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\svchost.exe[1212] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\svchost.exe[1212] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\svchost.exe[1212] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\svchost.exe[1212] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\svchost.exe[1212] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\svchost.exe[1212] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\svchost.exe[1212] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\svchost.exe[1212] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\svchost.exe[1212] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\stsystra.exe[1276] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\stsystra.exe[1276] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\stsystra.exe[1276] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\stsystra.exe[1276] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\stsystra.exe[1276] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\stsystra.exe[1276] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\stsystra.exe[1276] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\stsystra.exe[1276] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\stsystra.exe[1276] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\stsystra.exe[1276] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\WINDOWS\stsystra.exe[1276] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\Program Files\iTunes\iTunesHelper.exe[1304] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1320] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 00E4000A
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 00E5000A
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 00E3000C
.text C:\WINDOWS\System32\svchost.exe[1360] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\System32\svchost.exe[1360] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\System32\svchost.exe[1360] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\System32\svchost.exe[1360] USER32.dll!GetCursorPos 7E3A974E 5 Bytes JMP 0088000A
.text C:\WINDOWS\System32\svchost.exe[1360] ole32.dll!CoCreateInstance 774BF1AC 5 Bytes JMP 00FB000A
.text C:\WINDOWS\System32\svchost.exe[1360] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe[1420] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\svchost.exe[1452] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\WINDOWS\system32\svchost.exe[1452] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\WINDOWS\system32\svchost.exe[1452] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\WINDOWS\system32\svchost.exe[1452] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\WINDOWS\system32\svchost.exe[1452] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\WINDOWS\system32\svchost.exe[1452] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\WINDOWS\system32\svchost.exe[1452] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\WINDOWS\system32\svchost.exe[1452] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\WINDOWS\system32\svchost.exe[1452] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\WINDOWS\system32\svchost.exe[1452] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299
.text C:\WINDOWS\system32\svchost.exe[1452] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ntdll.dll!NtEnumerateValueKey 7C91D2EE 8 Bytes JMP 0BADADE3
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ntdll.dll!NtQueryDirectoryFile 7C91D76E 8 Bytes JMP 0BAE66A5
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ntdll.dll!NtResumeThread 7C91DB3E 8 Bytes JMP 0BAF4DEB
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ntdll.dll!NtSetInformationFile 7C91DC5E 8 Bytes JMP 0BADAB2D
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ntdll.dll!NtVdmControl 7C91DF1E 8 Bytes JMP 0BAE675B
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ntdll.dll!LdrLoadDll 7C92632D 8 Bytes JMP 0BAF4A78
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] USER32.dll!TranslateMessage 7E398BF6 8 Bytes JMP 0BADCA54
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] ADVAPI32.dll!CryptEncrypt 77DBE360 8 Bytes JMP 0BAED9C5
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!InternetQueryOptionA 404B0049 8 Bytes JMP 0BAEB481
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!InternetReadFile 404B654B 8 Bytes JMP 0BAEEAB0
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!HttpQueryInfoA 404B878D 8 Bytes JMP 0BAEB7A4
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!InternetCloseHandle 404B9088 8 Bytes JMP 0BAEBCF9
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!InternetQueryDataAvailable 404BBF83 8 Bytes JMP 0BAEE9C0
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!HttpAddRequestHeadersA 404BCF4E 8 Bytes JMP 0BADDD81
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!HttpOpenRequestA 404BD508 8 Bytes JMP 0BAEB36C
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!HttpSendRequestW 404BFABE 8 Bytes JMP 0BAF1B7A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!HttpSendRequestA 404CEE89 8 Bytes JMP 0BAF1A1C
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!InternetReadFileExA 404D3381 8 Bytes JMP 0BAEEBCA
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WININET.dll!InternetWriteFile 4051608E 8 Bytes JMP 0BAF1CD8
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] CRYPT32.dll!PFXImportCertStore 77A4FF8F 8 Bytes JMP 0BAE20ED
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[1536] WS2_32.dll!send 719F4C27 8 Bytes JMP 0BAEE299