oneill2004uk
Posts: 16 +0
Computer at works picked up the following couple of viruses so AVG says :-
Win32/zbot.g
Trojan horse rider.mpr
Trojan horse crystic.bgf
Don't want to have to reformat it if i can help it as its connected to a Cad Cutting System and we had to get someone to come in and install it last time which cost loads
I've followed the "6-step Viruses...." instructions and produced the following logs :-
(p.s. i forgot to put the MBAM log on my usb drive so i'll have to post that tomorrow morning sorry.)
GMER LOG PART 1
GMER log------------------------------------------------------
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-10 15:45:36
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3160815AS rev.4.AAA
Running: k87m9wmw.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\pgtdypob.sys
---- System - GMER 1.0.15 ----
SSDT BA7F77D4 ZwClose
SSDT BA7F778E ZwCreateKey
SSDT BA7F77DE ZwCreateSection
SSDT BA7F7784 ZwCreateThread
SSDT BA7F7793 ZwDeleteKey
SSDT BA7F779D ZwDeleteValueKey
SSDT BA7F77CF ZwDuplicateObject
SSDT BA7F77A2 ZwLoadKey
SSDT BA7F7770 ZwOpenProcess
SSDT BA7F7775 ZwOpenThread
SSDT BA7F77AC ZwReplaceKey
SSDT BA7F77A7 ZwRestoreKey
SSDT BA7F77E3 ZwSetContextThread
SSDT BA7F7798 ZwSetValueKey
SSDT BA7F777F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
? ecael.sys The system cannot find the file specified. !
.text atapi.sys B9F11852 1 Byte [CC] {INT 3 }
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB95C3360, 0x307F47, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\ctfmon.exe[256] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\ctfmon.exe[256] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\ctfmon.exe[256] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\ctfmon.exe[256] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
? C:\WINDOWS\system32\svchost.exe[512] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\svchost.exe[512] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2006637E
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2005A164
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200661FA
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20060BA0
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
? C:\WINDOWS\system32\services.exe[772] time/date stamp mismatch; unknown module: NTDSAPI.dllunknown module: NCObjAPI.DLLunknown module: SCESRV.dllunknown module: umpnpmgr.dll
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\services.exe[772] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\lsass.exe[784] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\system32\svchost.exe[948] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[948] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
? C:\WINDOWS\system32\svchost.exe[1032] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1032] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[1032] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[1032] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[1032] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\System32\svchost.exe[1088] time/date stamp mismatch;
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\System32\svchost.exe[1088] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 200B32FB
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 200B2F86
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 200B2FDC
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 200B33B6
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 200B281D
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpOpenRequestW 3D94FBFB 5 Bytes JMP 200B33E3
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestA 3D95EE91 5 Bytes JMP 200B27E8
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 200B3410
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetReadFileExW 3D963229 5 Bytes JMP 200B31E0
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetReadFileExA 3D963261 5 Bytes JMP 200B3139
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetWriteFile 3D9A6086 5 Bytes JMP 200B284F
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 200B3437
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestExA 3D9BA65A 5 Bytes JMP 200B27A2
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestExW 3D9BA6B3 5 Bytes JMP 200B275C
? C:\WINDOWS\system32\svchost.exe[1180] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\system32\svchost.exe[1232] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
.text C:\WINDOWS\system32\spoolsv.exe[1412] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\spoolsv.exe[1412] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\spoolsv.exe[1412] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\spoolsv.exe[1412] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\Explorer.EXE[1708] time/date stamp mismatch; unknown module: WINMM.dllunknown module: SETUPAPI.dllunknown module: WINSTA.dllunknown module: OLEACC.dllunknown module: BROWSEUI.dllunknown module: OLEAUT32.dllunknown module: SHDOCVW.dllunknown module: UxTheme.dll
.text C:\WINDOWS\Explorer.EXE[1708] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\Explorer.EXE[1708] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\Explorer.EXE[1708] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\Explorer.EXE[1708] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 200B32FB
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 200B2F86
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 200B2FDC
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 200B33B6
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 200B281D
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpOpenRequestW 3D94FBFB 5 Bytes JMP 200B33E3
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestA 3D95EE91 5 Bytes JMP 200B27E8
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 200B3410
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetReadFileExW 3D963229 5 Bytes JMP 200B31E0
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetReadFileExA 3D963261 5 Bytes JMP 200B3139
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetWriteFile 3D9A6086 5 Bytes JMP 200B284F
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 200B3437
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestExA 3D9BA65A 5 Bytes JMP 200B27A2
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestExW 3D9BA6B3 5 Bytes JMP 200B275C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
Win32/zbot.g
Trojan horse rider.mpr
Trojan horse crystic.bgf
Don't want to have to reformat it if i can help it as its connected to a Cad Cutting System and we had to get someone to come in and install it last time which cost loads
I've followed the "6-step Viruses...." instructions and produced the following logs :-
(p.s. i forgot to put the MBAM log on my usb drive so i'll have to post that tomorrow morning sorry.)
GMER LOG PART 1
GMER log------------------------------------------------------
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-10 15:45:36
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3160815AS rev.4.AAA
Running: k87m9wmw.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\pgtdypob.sys
---- System - GMER 1.0.15 ----
SSDT BA7F77D4 ZwClose
SSDT BA7F778E ZwCreateKey
SSDT BA7F77DE ZwCreateSection
SSDT BA7F7784 ZwCreateThread
SSDT BA7F7793 ZwDeleteKey
SSDT BA7F779D ZwDeleteValueKey
SSDT BA7F77CF ZwDuplicateObject
SSDT BA7F77A2 ZwLoadKey
SSDT BA7F7770 ZwOpenProcess
SSDT BA7F7775 ZwOpenThread
SSDT BA7F77AC ZwReplaceKey
SSDT BA7F77A7 ZwRestoreKey
SSDT BA7F77E3 ZwSetContextThread
SSDT BA7F7798 ZwSetValueKey
SSDT BA7F777F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
? ecael.sys The system cannot find the file specified. !
.text atapi.sys B9F11852 1 Byte [CC] {INT 3 }
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB95C3360, 0x307F47, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\ctfmon.exe[256] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\ctfmon.exe[256] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\ctfmon.exe[256] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\ctfmon.exe[256] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
? C:\WINDOWS\system32\svchost.exe[512] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\svchost.exe[512] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\svchost.exe[512] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2006637E
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2005A164
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200661FA
.text C:\WINDOWS\system32\SearchFilterHost.exe[680] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20060BA0
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[708] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
? C:\WINDOWS\system32\services.exe[772] time/date stamp mismatch; unknown module: NTDSAPI.dllunknown module: NCObjAPI.DLLunknown module: SCESRV.dllunknown module: umpnpmgr.dll
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\services.exe[772] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\services.exe[772] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\lsass.exe[784] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\lsass.exe[784] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\system32\svchost.exe[948] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[948] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[948] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[1028] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
? C:\WINDOWS\system32\svchost.exe[1032] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1032] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[1032] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[1032] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[1032] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[1032] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\System32\svchost.exe[1088] time/date stamp mismatch;
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\System32\svchost.exe[1088] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 200B32FB
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 200B2F86
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 200B2FDC
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 200B33B6
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 200B281D
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpOpenRequestW 3D94FBFB 5 Bytes JMP 200B33E3
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestA 3D95EE91 5 Bytes JMP 200B27E8
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 200B3410
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetReadFileExW 3D963229 5 Bytes JMP 200B31E0
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetReadFileExA 3D963261 5 Bytes JMP 200B3139
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetWriteFile 3D9A6086 5 Bytes JMP 200B284F
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 200B3437
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestExA 3D9BA65A 5 Bytes JMP 200B27A2
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestExW 3D9BA6B3 5 Bytes JMP 200B275C
? C:\WINDOWS\system32\svchost.exe[1180] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\system32\svchost.exe[1232] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\svchost.exe[1232] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe[1316] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
.text C:\WINDOWS\system32\spoolsv.exe[1412] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\system32\spoolsv.exe[1412] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\system32\spoolsv.exe[1412] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\system32\spoolsv.exe[1412] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\WINDOWS\system32\spoolsv.exe[1412] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\WINDOWS\system32\SearchIndexer.exe[1556] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B197B
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B1CA5
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B1FBE
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B192D
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B1E02
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B1C36
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B1D1A
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B1EDD
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1564] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B1D8B
? C:\WINDOWS\Explorer.EXE[1708] time/date stamp mismatch; unknown module: WINMM.dllunknown module: SETUPAPI.dllunknown module: WINSTA.dllunknown module: OLEACC.dllunknown module: BROWSEUI.dllunknown module: OLEAUT32.dllunknown module: SHDOCVW.dllunknown module: UxTheme.dll
.text C:\WINDOWS\Explorer.EXE[1708] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B637E
.text C:\WINDOWS\Explorer.EXE[1708] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA164
.text C:\WINDOWS\Explorer.EXE[1708] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200B61FA
.text C:\WINDOWS\Explorer.EXE[1708] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0BA0
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 200B32FB
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 200B2F86
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 200B2FDC
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 200B33B6
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 200B281D
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpOpenRequestW 3D94FBFB 5 Bytes JMP 200B33E3
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestA 3D95EE91 5 Bytes JMP 200B27E8
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 200B3410
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetReadFileExW 3D963229 5 Bytes JMP 200B31E0
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetReadFileExA 3D963261 5 Bytes JMP 200B3139
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetWriteFile 3D9A6086 5 Bytes JMP 200B284F
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 200B3437
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestExA 3D9BA65A 5 Bytes JMP 200B27A2
.text C:\WINDOWS\Explorer.EXE[1708] WININET.dll!HttpSendRequestExW 3D9BA6B3 5 Bytes JMP 200B275C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[2124] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 2002197B
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 20021CA5
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 20021FBE
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!send 71AB4C27 5 Bytes JMP 2002192D
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 20021E02
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!recv 71AB676F 5 Bytes JMP 20021C36
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 20021D1A
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 20021EDD
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 20021D8B
.text C:\Program Files\Java\jre6\bin\jqs.exe[2192] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 2002637E
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 2001A164
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 200261FA
.text C:\WINDOWS\system32\CAP3RSK.EXE[2264] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 20020BA0