Many thanks for the download Broni
This is the GMER kog report:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-12-07 07:42:06
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-5 Hitachi_HDP725050GLA360 rev.GM4OA5CA
Running: 967xzn8x.exe; Driver: C:\DOCUME~1\Pete\LOCALS~1\Temp\fwtcakow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB5604F3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB5604FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB5605080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB560511C]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB90AE360, 0x30AD87, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[156] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[176] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
? C:\WINDOWS\system32\services.exe[808] time/date stamp mismatch; unknown module: NTDSAPI.dllunknown module: NCObjAPI.DLLunknown module: SCESRV.dllunknown module: umpnpmgr.dll
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\services.exe[808] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\system32\services.exe[808] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
.text C:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\lsass.exe[820] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\lsass.exe[820] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\lsass.exe[820] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\system32\lsass.exe[820] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
? C:\WINDOWS\system32\svchost.exe[988] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
? C:\WINDOWS\system32\svchost.exe[1060] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1060] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\svchost.exe[1060] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\svchost.exe[1060] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\svchost.exe[1060] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\svchost.exe[1060] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\system32\svchost.exe[1060] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
? C:\WINDOWS\System32\svchost.exe[1100] time/date stamp mismatch;
.text C:\WINDOWS\System32\svchost.exe[1100] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\System32\svchost.exe[1100] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\System32\svchost.exe[1100] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\System32\svchost.exe[1100] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\System32\svchost.exe[1100] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\System32\svchost.exe[1100] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 200B3715
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 200B33A0
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetQueryDataAvailable 3D94BF7F 5 Bytes JMP 200B33F6
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 200B37D0
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 200B2C37
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!HttpOpenRequestW 3D94FBFB 5 Bytes JMP 200B37FD
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!HttpSendRequestA 3D95EE91 5 Bytes JMP 200B2C02
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 200B382A
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetReadFileExW 3D963229 5 Bytes JMP 200B35FA
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetReadFileExA 3D963261 5 Bytes JMP 200B3553
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetWriteFile 3D9A6086 5 Bytes JMP 200B2C69
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 200B3851
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!HttpSendRequestExA 3D9BA65A 5 Bytes JMP 200B2BBC
.text C:\WINDOWS\System32\svchost.exe[1100] WININET.dll!HttpSendRequestExW 3D9BA6B3 5 Bytes JMP 200B2B76
? C:\WINDOWS\system32\svchost.exe[1156] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1156] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\svchost.exe[1156] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\svchost.exe[1156] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\svchost.exe[1156] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\svchost.exe[1156] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\system32\svchost.exe[1156] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
? C:\WINDOWS\system32\svchost.exe[1184] time/date stamp mismatch;
.text C:\WINDOWS\system32\svchost.exe[1184] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\svchost.exe[1184] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\svchost.exe[1184] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\svchost.exe[1184] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\svchost.exe[1184] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 200B1D95
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!recvfrom 71AB2FF7 5 Bytes JMP 200B20BF
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 200B23D8
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!send 71AB4C27 5 Bytes JMP 200B1D47
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 200B221C
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!recv 71AB676F 5 Bytes JMP 200B2050
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 200B2134
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 200B22F7
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 200B21A5
.text C:\WINDOWS\system32\spoolsv.exe[1344] ntdll.dll!NtQueryDirectoryFile 7C90D76E 5 Bytes JMP 200B6798
.text C:\WINDOWS\system32\spoolsv.exe[1344] ntdll.dll!NtResumeThread 7C90DB3E 5 Bytes JMP 200AA3DB
.text C:\WINDOWS\system32\spoolsv.exe[1344] ntdll.dll!LdrLoadDll 7C91632D 2 Bytes JMP 200B6614
.text C:\WINDOWS\system32\spoolsv.exe[1344] ntdll.dll!LdrLoadDll + 3 7C916330 2 Bytes [7A, A3] {JP 0xffffffffffffffa5}
.text C:\WINDOWS\system32\spoolsv.exe[1344] USER32.dll!TranslateMessage 7E418BF6 5 Bytes JMP 200B0FB8
.text C:\WINDOWS\system32\spoolsv.exe[1344] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 200B3715
.text C:\WINDOWS\system32\spoolsv.exe[1344] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 200B33A0
.text C:\WINDOWS\system32\spoolsv.exe[1344] WININET.dll!InternetQueryDataAvailable 3D94BF7F 5 Bytes JMP 200B33F6
.text C:\WINDOWS\system32\spoolsv.exe[1344] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 200B37D0
.text C:\WINDOWS\system32\spoolsv.exe[1344] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 200B2C37
.text C:\WINDOWS\system32\spoolsv.exe[1344] WININET.dll!HttpOpenRequestW 3D94FBFB 5 Bytes JMP 200B37FD
continued on next post