all right, sorry for the wait on that, had some trouble with my connection recently, unfortunately my computer, well, I wont get into it, since it has nothing to do with the programming, well, here is the information from that scan.
GMER 1.0.14.14205 -
http://www.gmer.net
Rootkit scan 2008-05-04 00:35:58
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT \??\C:\WINDOWS\widuxngq.sys ZwCreateKey [0xF3D6F95F] <-- ROOTKIT !!!
SSDT \??\C:\WINDOWS\widuxngq.sys ZwOpenKey [0xF3D6FA13] <-- ROOTKIT !!!
SSDT \??\C:\WINDOWS\widuxngq.sys ZwTerminateProcess [0xF3D71531] <-- ROOTKIT !!!
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF3CB697C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF3CB692A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF3CB693E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF3CB6A2F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF3CB6A5B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF3CB6AC9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF3CB6AB3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF3CB69BC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF3CB6AF5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF3CB6902]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF3CB6916]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF3CB6990]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF3CB6B31]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF3CB6A9D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF3CB6A87]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF3CB6A45]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF3CB6B1D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF3CB6B09]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF3CB6968]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF3CB6954]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF3CB6A71]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF3CB6ADF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF3CB69D2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF3CB69A6]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.14 ----
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B19D2 1 Byte [ E9 ]
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection + 2 805B19D4 3 Bytes [ 4F, 70, 73 ]
? C:\WINDOWS\widuxngq.sys The system cannot find the file specified.
---- User code sections - GMER 1.0.14 ----
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[764] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[764] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00CE0FEF
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00CE0F6D
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00CE0058
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00CE0047
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00CE0036
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00CE0FA8
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00CE00B5
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00CE00A4
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00CE00C6
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00CE0F2D
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00CE0F1C
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00CE0025
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00CE0FDE
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00CE007D
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00CE0014
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00CE0FC3
.text C:\WINDOWS\system32\services.exe[892] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00CE0F52
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00A40FA8
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00A40F61
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00A40FC3
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00A40FD4
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00A4001E
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00A40F7C
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00A40FEF
.text C:\WINDOWS\system32\services.exe[892] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00A40F8D
.text C:\WINDOWS\system32\services.exe[892] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00A10000
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00B60000
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00B60080
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00B60F81
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00B60F9E
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00B60FAF
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00B600B8
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00B6009D
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00B60F30
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00B600D3
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00B600E4
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00B6005B
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00B60FE5
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00B60F70
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00B60036
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00B6001B
.text C:\WINDOWS\system32\lsass.exe[904] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00B60F4B
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00B50036
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00B50F94
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00B50025
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00B5000A
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00B50FA5
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00B50047
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00B50FEF
.text C:\WINDOWS\system32\lsass.exe[904] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00B50FCA
.text C:\WINDOWS\system32\lsass.exe[904] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B30FEF
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E4000A
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E4009A
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E40FAF
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E4007D
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E4006C
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E40FDB
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E400B5
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E40F6F
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E40F48
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E400E1
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00E400FC
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00E40FCA
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00E4001B
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00E40F80
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00E40051
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00E4002C
.text C:\WINDOWS\system32\svchost.exe[1052] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00E400D0
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00E30FDB
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00E30F9E
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00E3002C
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00E3001B
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00E30FAF
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00E30051
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00E3000A
.text C:\WINDOWS\system32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00E30FCA
.text C:\WINDOWS\system32\svchost.exe[1052] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00E1000A
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00BA0FEF
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00BA0067
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00BA0F72
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00BA0F8D
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00BA0F9E
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00BA0040
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00BA008E
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00BA0F46
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00BA0F17
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00BA00B0
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00BA00CB
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00BA0FAF
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00BA000A
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00BA0F57
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00BA0025
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00BA0FCA
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00BA009F
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00B9000A
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00B90F8A
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00B90FB9
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00B90FD4
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00B90047
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00B90036
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00B90FE5
.text C:\WINDOWS\system32\svchost.exe[1112] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00B90025
.text C:\WINDOWS\system32\svchost.exe[1112] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B70000
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 02650FEF
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 02650047
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 02650F52
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 02650F79
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 02650F8A
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 02650025
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 02650F12
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 02650058
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 02650EDC
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 02650EF7
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 02650086
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 02650036
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 02650FD4
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 02650F37
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 02650FB9
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0265000A
.text C:\WINDOWS\System32\svchost.exe[1148] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 02650075
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 02640FC3
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 02640054
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 02640FD4
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 0264000A
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0264002F
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 02640F8D
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 02640FEF
.text C:\WINDOWS\System32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 02640FA8
.text C:\WINDOWS\System32\svchost.exe[1148] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 02620000
.text C:\WINDOWS\System32\svchost.exe[1148] WININET.dll!InternetOpenA 42C2C851 5 Bytes JMP 01C30000
.text C:\WINDOWS\System32\svchost.exe[1148] WININET.dll!InternetOpenW 42C2CE81 5 Bytes JMP 01C30FE5
.text C:\WINDOWS\System32\svchost.exe[1148] WININET.dll!InternetOpenUrlA 42C30BAA 5 Bytes JMP 01C3001B
.text C:\WINDOWS\System32\svchost.exe[1148] WININET.dll!InternetOpenUrlW 42C7AE09 5 Bytes JMP 01C3002C
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 008C0000
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 008C0F4D
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 008C0F5E
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 008C0F79
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 008C0F8A
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 008C0FAF
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008C0073
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 008C0F21
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008C0F10
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008C00A9
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008C00BA
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 008C0036
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 008C0FE5
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 008C0F32
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 008C001B
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 008C0FCA
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 008C0084
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008B000A
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008B002C
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008B0FB9
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008B0FD4
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008B0F6F
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008B001B
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008B0FE5
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008B0F9E
.text C:\WINDOWS\system32\svchost.exe[1196] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00890FEF
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 009A0000
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009A0F63
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 009A0F74
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 009A0058
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 009A0FA5
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 009A002C
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009A0090
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009A0F48
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 009A0F12
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009A0F2D
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 009A00BC
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 009A0047
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 009A0011
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 009A0073
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 009A0FC0
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 009A0FDB
.text C:\WINDOWS\system32\svchost.exe[1340] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 009A00AB
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0080002F
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00800FAF
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0080001E
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00800FDE
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0080006C
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00800051
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00800040
.text C:\WINDOWS\system32\svchost.exe[1340] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007E0FEF
.text C:\WINDOWS\system32\svchost.exe[1340] WININET.dll!InternetOpenA 42C2C851 5 Bytes JMP 007D000A
.text C:\WINDOWS\system32\svchost.exe[1340] WININET.dll!InternetOpenW 42C2CE81 5 Bytes JMP 007D001B
.text C:\WINDOWS\system32\svchost.exe[1340] WININET.dll!InternetOpenUrlA 42C30BAA 5 Bytes JMP 007D0040
.text C:\WINDOWS\system32\svchost.exe[1340] WININET.dll!InternetOpenUrlW 42C7AE09 5 Bytes JMP 007D0FE5
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0094000A
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00940F63
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00940058
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00940047
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00940F8A
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00940FC0
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00940095
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00940084
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00940F10
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00940F2B
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00940EFF
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00940FAF
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0094001B
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00940073
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00940FDB
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0094002C
.text C:\WINDOWS\system32\svchost.exe[1820] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00940F3C
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00930051
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0093009B
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0093002C
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 0093001B
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00930FD4
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00930FE5
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 0093000A
.text C:\WINDOWS\system32\svchost.exe[1820] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0093006C
.text C:\WINDOWS\system32\svchost.exe[1820] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00910000
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 009F0000
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009F0065
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 009F0F70
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 009F004A
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 009F0F8D
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 009F0FB9
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009F00A7
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009F0F5F
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 009F00D3
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009F0F3A
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 009F0F1F
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 009F0F9E
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 009F0FEF
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 009F0080
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 009F0FCA
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 009F0025
.text C:\WINDOWS\system32\svchost.exe[1852] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 009F00B8
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 009E0036
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 009E006C
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 009E0FE5
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 009E001B
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 009E0FAF
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 009E0FC0
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 009E0000
.text C:\WINDOWS\system32\svchost.exe[1852] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 009E0051
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 012D0000
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 012D0073
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 012D0062
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 012D0F94
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 012D0FAF
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 012D0036
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 012D0F2D
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 012D0F48
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 012D0F08
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 012D00AB
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 012D00BC
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 012D0051
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 012D0FDB
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 012D0F63
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 012D0FCA
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 012D0011
.text C:\WINDOWS\Explorer.EXE[2252] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 012D0090
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 012C0014
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 012C0F79
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 012C0FC3
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 012C0FD4
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 012C0F8A
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 012C0036
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 012C0FEF
.text C:\WINDOWS\Explorer.EXE[2252] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 012C0025
.text C:\WINDOWS\Explorer.EXE[2252] WININET.dll!InternetOpenA 42C2C851 5 Bytes JMP 00D60000
.text C:\WINDOWS\Explorer.EXE[2252] WININET.dll!InternetOpenW 42C2CE81 5 Bytes JMP 00D6001B
.text C:\WINDOWS\Explorer.EXE[2252] WININET.dll!InternetOpenUrlA 42C30BAA 5 Bytes JMP 00D60036
.text C:\WINDOWS\Explorer.EXE[2252] WININET.dll!InternetOpenUrlW 42C7AE09 5 Bytes JMP 00D60051
.text C:\WINDOWS\Explorer.EXE[2252] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 012A000A
.text C:\Program Files\Messenger\msmsgs.exe[2776] kernel32.dll!