.text C:\Windows\system32\SearchProtocolHost.exe[2536] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\SearchProtocolHost.exe[2536] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2548] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2548] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2548] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2604] kernel32.dll!CreateThread + 1A 76B246E2 4 Bytes CALL 0044AD11 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] kernel32.dll!CreateThread + 1A 76B246E2 4 Bytes CALL 0044AB89 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!GetStartupInfoW 76AE1929 5 Bytes JMP 00FE00A5
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!GetStartupInfoA 76AE19C9 5 Bytes JMP 00FE0094
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateProcessW 76AE1C01 5 Bytes JMP 00FE00D1
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateProcessA 76AE1C36 5 Bytes JMP 00FE0F3B
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!VirtualProtect 76AE1DD1 5 Bytes JMP 00FE005E
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateNamedPipeW 76AE5C44 5 Bytes JMP 00FE0FC3
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 00FE0F90
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryW 76B0361F 5 Bytes JMP 00FE0FB2
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!VirtualProtectEx 76B08D7E 5 Bytes JMP 00FE006F
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryExA 76B09469 5 Bytes JMP 00FE0FA1
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryA 76B09491 5 Bytes JMP 00FE002F
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreatePipe 76B10284 5 Bytes JMP 00FE0F60
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!GetProcAddress 76B2B8B6 5 Bytes JMP 00FE0F20
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateFileW 76B2CC4E 5 Bytes JMP 00FE0FE5
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateFileA 76B2CF71 5 Bytes JMP 00FE0000
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateNamedPipeA 76B7430E 5 Bytes JMP 00FE0FD4
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!WinExec 76B754FF 5 Bytes JMP 00FE00B6
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_wsystem 76A88A47 5 Bytes JMP 00FD0F92
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!system 76A88B63 5 Bytes JMP 00FD0FA3
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_creat 76A8C6F1 5 Bytes JMP 00FD0FC8
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_open 76A8DA7E 5 Bytes JMP 00FD0000
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_wcreat 76A8DC9E 5 Bytes JMP 00FD001D
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_wopen 76A8DE79 5 Bytes JMP 00FD0FE3
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyExA 75E6B5E7 5 Bytes JMP 00FC0080
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyA 75E6B8AE 5 Bytes JMP 00FC0FD4
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyA 75E70BF5 5 Bytes JMP 00FC0000
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyW 75E7B83D 5 Bytes JMP 00FC005B
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyExW 75E7BCE1 5 Bytes JMP 00FC0091
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyExA 75E7D4E8 5 Bytes JMP 00FC0FEF
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyW 75E83CB0 5 Bytes JMP 00FC0025
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyExW 75E8F09D 5 Bytes JMP 00FC004A
.text C:\Windows\system32\svchost.exe[2740] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[2740] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[2740] WS2_32.dll!socket 778136D1 5 Bytes JMP 00FF0FEF
.text C:\Windows\System32\rundll32.exe[2788] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetForegroundWindow 7786B5F5 6 Bytes JMP 5F0D0F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowPos 778721FE 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowPos + 4 77872202 2 Bytes [12, 5F]
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!ChangeDisplaySettingsExA 778913E2 6 Bytes JMP 5F140F5A
.text C:\Windows\system32\SearchProtocolHost.exe[2536] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2548] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2548] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2548] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2604] kernel32.dll!CreateThread + 1A 76B246E2 4 Bytes CALL 0044AD11 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] kernel32.dll!CreateThread + 1A 76B246E2 4 Bytes CALL 0044AB89 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2724] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!GetStartupInfoW 76AE1929 5 Bytes JMP 00FE00A5
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!GetStartupInfoA 76AE19C9 5 Bytes JMP 00FE0094
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateProcessW 76AE1C01 5 Bytes JMP 00FE00D1
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateProcessA 76AE1C36 5 Bytes JMP 00FE0F3B
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!VirtualProtect 76AE1DD1 5 Bytes JMP 00FE005E
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateNamedPipeW 76AE5C44 5 Bytes JMP 00FE0FC3
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 00FE0F90
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryW 76B0361F 5 Bytes JMP 00FE0FB2
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!VirtualProtectEx 76B08D7E 5 Bytes JMP 00FE006F
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryExA 76B09469 5 Bytes JMP 00FE0FA1
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!LoadLibraryA 76B09491 5 Bytes JMP 00FE002F
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreatePipe 76B10284 5 Bytes JMP 00FE0F60
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!GetProcAddress 76B2B8B6 5 Bytes JMP 00FE0F20
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateFileW 76B2CC4E 5 Bytes JMP 00FE0FE5
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateFileA 76B2CF71 5 Bytes JMP 00FE0000
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!CreateNamedPipeA 76B7430E 5 Bytes JMP 00FE0FD4
.text C:\Windows\system32\svchost.exe[2740] kernel32.dll!WinExec 76B754FF 5 Bytes JMP 00FE00B6
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_wsystem 76A88A47 5 Bytes JMP 00FD0F92
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!system 76A88B63 5 Bytes JMP 00FD0FA3
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_creat 76A8C6F1 5 Bytes JMP 00FD0FC8
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_open 76A8DA7E 5 Bytes JMP 00FD0000
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_wcreat 76A8DC9E 5 Bytes JMP 00FD001D
.text C:\Windows\system32\svchost.exe[2740] msvcrt.dll!_wopen 76A8DE79 5 Bytes JMP 00FD0FE3
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyExA 75E6B5E7 5 Bytes JMP 00FC0080
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyA 75E6B8AE 5 Bytes JMP 00FC0FD4
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyA 75E70BF5 5 Bytes JMP 00FC0000
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyW 75E7B83D 5 Bytes JMP 00FC005B
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegCreateKeyExW 75E7BCE1 5 Bytes JMP 00FC0091
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyExA 75E7D4E8 5 Bytes JMP 00FC0FEF
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyW 75E83CB0 5 Bytes JMP 00FC0025
.text C:\Windows\system32\svchost.exe[2740] ADVAPI32.dll!RegOpenKeyExW 75E8F09D 5 Bytes JMP 00FC004A
.text C:\Windows\system32\svchost.exe[2740] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[2740] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[2740] WS2_32.dll!socket 778136D1 5 Bytes JMP 00FF0FEF
.text C:\Windows\System32\rundll32.exe[2788] kernel32.dll!LoadLibraryExW 76B030C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowsHookExW 77867B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetForegroundWindow 7786B5F5 6 Bytes JMP 5F0D0F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowPos 778721FE 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowPos + 4 77872202 2 Bytes [12, 5F]
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!SetWindowsHookExA 7788BB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\rundll32.exe[2788] USER32.dll!ChangeDisplaySettingsExA 778913E2 6 Bytes JMP 5F140F5A