Gmer Code:
GMER Logfile:
Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-04-01 17:38:37
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9320325AS rev.0020LVM1 298,09GB
Running: hls7unv5.exe; Driver: C:\Users\Kunde\AppData\Local\Temp\ugloqpob.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRequestWaitReplyPort + 1495 82C469E5 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C80312 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\drivers\ayxtqiyu.sys Das System kann den angegebenen Pfad nicht finden. !
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\svchost.exe[328] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[328] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[484] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\lsass.exe[556] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[708] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[836] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[924] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[992] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1044] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!CopyFileExW 76C0B348 7 Bytes JMP 756D9AF0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!MoveFileWithProgressW 76C18E9C 5 Bytes JMP 756D9C10 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] ole32.dll!CoCreateInstance 76DA9D0B 8 Bytes JMP 756DA2E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WININET.dll!InternetReadFile 772D9EA0 5 Bytes JMP 756D4E80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WININET.dll!InternetOpenA 772DEEC0 5 Bytes JMP 756D4EE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WININET.dll!InternetQueryDataAvailable 773254D0 5 Bytes JMP 756D4EA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WININET.dll!InternetOpenUrlA 773A8180 5 Bytes JMP 756D4EC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\Explorer.EXE[1636] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!closesocket 776D3918 5 Bytes JMP 756D4DE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!WSAStartup 776D3AB2 7 Bytes JMP 756D4E40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!bind 776D4582 5 Bytes JMP 756D4E00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!accept 776D68B6 5 Bytes JMP 756D4E20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!recv 776D6B0E 5 Bytes JMP 756D4D60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!connect 776D6BDD 5 Bytes JMP 756D4DC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!send 776D6F01 5 Bytes JMP 756D4D40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!getpeername 776D7147 5 Bytes JMP 756D4DA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!listen 776DB001 5 Bytes JMP 756D4D80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[1876] WS2_32.dll!WSASocketA 776DC82A 5 Bytes JMP 756D4E60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\system32\svchost.exe[2876] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\rundll32.exe[3584] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtCreateFile + 6 777B560E 4 Bytes [28, 54, 33, 00] {SUB [EBX+ESI+0x0], DL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtCreateFile + B 777B5613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtMapViewOfSection + 6 777B5C6E 4 Bytes [28, 57, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtMapViewOfSection + B 777B5C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenFile + 6 777B5D1E 4 Bytes [68, 54, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenFile + B 777B5D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenProcess + 6 777B5DCE 4 Bytes [A8, 55, 33, 00] {TEST AL, 0x55; XOR EAX, [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenProcess + B 777B5DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenProcessToken + B 777B5DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenProcessTokenEx + 6 777B5DEE 4 Bytes [A8, 56, 33, 00] {TEST AL, 0x56; XOR EAX, [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenProcessTokenEx + B 777B5DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenThread + 6 777B5E4E 4 Bytes [68, 55, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenThread + B 777B5E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenThreadToken + 6 777B5E5E 4 Bytes [68, 56, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenThreadToken + B 777B5E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtOpenThreadTokenEx + B 777B5E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtQueryAttributesFile + 6 777B5F7E 4 Bytes [A8, 54, 33, 00] {TEST AL, 0x54; XOR EAX, [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtQueryAttributesFile + B 777B5F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtQueryFullAttributesFile + B 777B6033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtSetInformationFile + 6 777B667E 4 Bytes [28, 55, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtSetInformationFile + B 777B6683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtSetInformationThread + 6 777B66DE 4 Bytes [28, 56, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtSetInformationThread + B 777B66E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtUnmapViewOfSection + 6 777B69FE 4 Bytes [68, 57, 33, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ntdll.dll!NtUnmapViewOfSection + B 777B6A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756DA1F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] kernel32.dll!CreateActCtxW 76C157ED 5 Bytes JMP 756D98F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] kernel32.dll!CreateFileW 76C1E955 5 Bytes JMP 756D9FD0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756DA110 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] kernel32.dll!ReplaceFile 76C317C0 5 Bytes JMP 756D99B0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] USER32.dll!CreateWindowExW 7696EC7C 5 Bytes JMP 756D9F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] SHELL32.dll!SHExtractIconsW 75D0543B 5 Bytes JMP 756D3D90 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3976] ole32.dll!StgOpenStorageEx 76DD6D42 5 Bytes JMP 756BDDB0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtCreateFile + 6 777B560E 4 Bytes [28, 44, CB, 00] {SUB [EBX+ECX*8+0x0], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtCreateFile + B 777B5613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtMapViewOfSection + 6 777B5C6E 4 Bytes [28, 47, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtMapViewOfSection + B 777B5C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenFile + 6 777B5D1E 4 Bytes [68, 44, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenFile + B 777B5D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenProcess + 6 777B5DCE 4 Bytes [A8, 45, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenProcess + B 777B5DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenProcessToken + B 777B5DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenProcessTokenEx + 6 777B5DEE 4 Bytes [A8, 46, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenProcessTokenEx + B 777B5DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenThread + 6 777B5E4E 4 Bytes [68, 45, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenThread + B 777B5E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenThreadToken + 6 777B5E5E 4 Bytes [68, 46, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenThreadToken + B 777B5E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtOpenThreadTokenEx + B 777B5E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtQueryAttributesFile + 6 777B5F7E 4 Bytes [A8, 44, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtQueryAttributesFile + B 777B5F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtQueryFullAttributesFile + B 777B6033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtSetInformationFile + 6 777B667E 4 Bytes [28, 45, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtSetInformationFile + B 777B6683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtSetInformationThread + 6 777B66DE 4 Bytes [28, 46, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtSetInformationThread + B 777B66E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtUnmapViewOfSection + 6 777B69FE 4 Bytes [68, 47, CB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ntdll.dll!NtUnmapViewOfSection + B 777B6A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756DA1F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] kernel32.dll!CreateActCtxW 76C157ED 5 Bytes JMP 756D98F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] kernel32.dll!CreateFileW 76C1E955 5 Bytes JMP 756D9FD0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756DA110 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] kernel32.dll!ReplaceFile 76C317C0 5 Bytes JMP 756D99B0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] USER32.dll!CreateWindowExW 7696EC7C 5 Bytes JMP 756D9F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] SHELL32.dll!SHExtractIconsW 75D0543B 5 Bytes JMP 756D3D90 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4112] ole32.dll!StgOpenStorageEx 76DD6D42 5 Bytes JMP 756BDDB0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] ntdll.dll!RtlExitUserThread 7779F608 5 Bytes JMP 756D50E0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] ntdll.dll!KiUserExceptionDispatcher 777B7048 5 Bytes JMP 756D8710 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] ntdll.dll!LdrLoadDll 777D22AE 5 Bytes JMP 756D4F00 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!CreateProcessA 76BD2082 5 Bytes JMP 756D5140 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!VirtualProtect 76C12CDD 5 Bytes JMP 756D4FC0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!LoadLibraryExA 76C14576 5 Bytes JMP 756D5040 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756D5020 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!GlobalAlloc 76C1A235 5 Bytes JMP 756D5080 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!GetProcAddress 76C1CD44 5 Bytes JMP 756D50C0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!LoadLibraryA 76C1DD15 5 Bytes JMP 756D5060 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!CreateFileA 76C1EB11 5 Bytes JMP 756D5160 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!LoadLibraryW 76C1EFF2 5 Bytes JMP 756D5000 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756D5330 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!WriteFile 76C254A6 5 Bytes JMP 756D4F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!ExitProcess 76C2BC9A 5 Bytes JMP 756D5100 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!CreateProcessInternalA 76C2C954 5 Bytes JMP 756D5120 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!WriteFileEx 76C355E5 5 Bytes JMP 756D4F40 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!GetThreadContext 76C38C8C 5 Bytes JMP 756D50A0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!WriteProcessMemory 76C39657 5 Bytes JMP 756D4F20 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!WinExec 76C5F22E 5 Bytes JMP 756D4F80 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!VirtualProtectEx 76C60269 5 Bytes JMP 756D4FA0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Windows\System32\svchost.exe[4208] kernel32.dll!SetThreadContext 76C60DE3 5 Bytes JMP 756D4FE0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtCreateFile + 6 777B560E 4 Bytes CALL 5A7A5627
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtCreateFile + B 777B5613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtMapViewOfSection + 6 777B5C6E 4 Bytes [28, EB, 14, 00] {SUB BL, CH; ADC AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtMapViewOfSection + B 777B5C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenFile + 6 777B5D1E 4 Bytes CALL 5A7A5D37
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenFile + B 777B5D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenProcess + 6 777B5DCE 4 Bytes JMP 5A7A5DE7
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenProcess + B 777B5DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenProcessToken + B 777B5DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenProcessTokenEx + 6 777B5DEE 4 Bytes JMP E2FF0014
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenProcessTokenEx + B 777B5DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenThread + 6 777B5E4E 4 Bytes JMP 5A7A5E67
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenThread + B 777B5E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenThreadToken + 6 777B5E5E 4 Bytes JMP E2FF0014
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenThreadToken + B 777B5E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtOpenThreadTokenEx + B 777B5E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtQueryAttributesFile + 6 777B5F7E 4 Bytes CALL 5A7A5F97
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtQueryAttributesFile + B 777B5F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtQueryFullAttributesFile + B 777B6033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtSetInformationFile + 6 777B667E 4 Bytes JMP 5A7A6697
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtSetInformationFile + B 777B6683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtSetInformationThread + 6 777B66DE 4 Bytes JMP E2FF0014
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtSetInformationThread + B 777B66E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtUnmapViewOfSection + 6 777B69FE 4 Bytes [68, EB, 14, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ntdll.dll!NtUnmapViewOfSection + B 777B6A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756DA1F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] kernel32.dll!CreateActCtxW 76C157ED 5 Bytes JMP 756D98F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] kernel32.dll!CreateFileW 76C1E955 5 Bytes JMP 756D9FD0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756DA110 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] kernel32.dll!ReplaceFile 76C317C0 5 Bytes JMP 756D99B0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] USER32.dll!CreateWindowExW 7696EC7C 5 Bytes JMP 756D9F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] SHELL32.dll!SHExtractIconsW 75D0543B 5 Bytes JMP 756D3D90 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4712] ole32.dll!StgOpenStorageEx 76DD6D42 5 Bytes JMP 756BDDB0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] ntdll.dll!NtMapViewOfSection + 6 777B5C6E 4 Bytes [18, 20, 27, 72]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] ntdll.dll!NtMapViewOfSection + B 777B5C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756DA1F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] kernel32.dll!CreateActCtxW 76C157ED 5 Bytes JMP 756D98F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] kernel32.dll!CreateFileW 76C1E955 5 Bytes JMP 756D9FD0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756DA110 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] kernel32.dll!ReplaceFile 76C317C0 5 Bytes JMP 756D99B0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] USER32.dll!CreateWindowExW 7696EC7C 5 Bytes JMP 756D9F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] SHELL32.dll!SHExtractIconsW 75D0543B 5 Bytes JMP 756D3D90 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4968] ole32.dll!StgOpenStorageEx 76DD6D42 5 Bytes JMP 756BDDB0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtCreateFile + 6 777B560E 4 Bytes [28, 38, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtCreateFile + B 777B5613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtMapViewOfSection + 6 777B5C6E 4 Bytes [28, 3B, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtMapViewOfSection + B 777B5C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenFile + 6 777B5D1E 4 Bytes [68, 38, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenFile + B 777B5D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenProcess + 6 777B5DCE 4 Bytes [A8, 39, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenProcess + B 777B5DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenProcessToken + B 777B5DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenProcessTokenEx + 6 777B5DEE 4 Bytes [A8, 3A, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenProcessTokenEx + B 777B5DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenThread + 6 777B5E4E 4 Bytes [68, 39, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenThread + B 777B5E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenThreadToken + 6 777B5E5E 4 Bytes [68, 3A, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenThreadToken + B 777B5E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtOpenThreadTokenEx + B 777B5E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtQueryAttributesFile + 6 777B5F7E 4 Bytes [A8, 38, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtQueryAttributesFile + B 777B5F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtQueryFullAttributesFile + B 777B6033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtSetInformationFile + 6 777B667E 4 Bytes [28, 39, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtSetInformationFile + B 777B6683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtSetInformationThread + 6 777B66DE 4 Bytes [28, 3A, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtSetInformationThread + B 777B66E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtUnmapViewOfSection + 6 777B69FE 4 Bytes [68, 3B, A2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ntdll.dll!NtUnmapViewOfSection + B 777B6A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756DA1F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] kernel32.dll!CreateActCtxW 76C157ED 5 Bytes JMP 756D98F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] kernel32.dll!CreateFileW 76C1E955 5 Bytes JMP 756D9FD0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756DA110 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] kernel32.dll!ReplaceFile 76C317C0 5 Bytes JMP 756D99B0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] USER32.dll!CreateWindowExW 7696EC7C 5 Bytes JMP 756D9F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] SHELL32.dll!SHExtractIconsW 75D0543B 5 Bytes JMP 756D3D90 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5564] ole32.dll!StgOpenStorageEx 76DD6D42 5 Bytes JMP 756BDDB0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtCreateFile + 6 777B560E 4 Bytes [28, 14, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtCreateFile + B 777B5613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtMapViewOfSection + 6 777B5C6E 4 Bytes [28, 17, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtMapViewOfSection + B 777B5C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenFile + 6 777B5D1E 4 Bytes [68, 14, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenFile + B 777B5D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenProcess + 6 777B5DCE 4 Bytes [A8, 15, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenProcess + B 777B5DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenProcessToken + B 777B5DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenProcessTokenEx + 6 777B5DEE 4 Bytes [A8, 16, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenProcessTokenEx + B 777B5DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenThread + 6 777B5E4E 4 Bytes [68, 15, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenThread + B 777B5E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenThreadToken + 6 777B5E5E 4 Bytes [68, 16, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenThreadToken + B 777B5E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtOpenThreadTokenEx + B 777B5E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtQueryAttributesFile + 6 777B5F7E 4 Bytes [A8, 14, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtQueryAttributesFile + B 777B5F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtQueryFullAttributesFile + B 777B6033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtSetInformationFile + 6 777B667E 4 Bytes [28, 15, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtSetInformationFile + B 777B6683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtSetInformationThread + 6 777B66DE 4 Bytes [28, 16, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtSetInformationThread + B 777B66E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtUnmapViewOfSection + 6 777B69FE 4 Bytes [68, 17, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ntdll.dll!NtUnmapViewOfSection + B 777B6A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] kernel32.dll!LoadLibraryExW 76C15189 5 Bytes JMP 756DA1F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] kernel32.dll!CreateActCtxW 76C157ED 5 Bytes JMP 756D98F0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] kernel32.dll!CreateFileW 76C1E955 5 Bytes JMP 756D9FD0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] kernel32.dll!FreeLibrary 76C1F017 5 Bytes JMP 756DA110 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] kernel32.dll!ReplaceFile 76C317C0 5 Bytes JMP 756D99B0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] USER32.dll!CreateWindowExW 7696EC7C 5 Bytes JMP 756D9F60 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] SHELL32.dll!SHExtractIconsW 75D0543B 5 Bytes JMP 756D3D90 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5984] ole32.dll!StgOpenStorageEx 76DD6D42 5 Bytes JMP 756BDDB0 C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
---- Devices - GMER 2.1 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active@1D4BF69E 156
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Superfetch@VirtualStoreSize 1322
---- EOF - GMER 2.1 ---- --- --- ---
Ich bedanke mich jetzt schon mal für die schnelle Reaktion, ich habe leider nur sporadisches Internet da ich im Ausland bin und mich auf WiFi in Cafés und Universität beschränken muss! |