Note: I have posted multiple times due to my GMER file being over 200KB and over 50K character limit... sorry if this causes any trouble
I have windows XP
so my brother put a virus on my computer... again...
I accessed a hidden folder and McAfee immediately notified me that it deleted a file called "SecurityCheck.exe" from the folder I was looking at and said it was a trojan. I scanned my computer after that and found 2 weird generic files which were also designated as trojans...
I assume that these might come back so I am wondering if I can get help disinfecting my computer...
Do these trojans steal information??
GMER is copy/pasted, the rest of the logs are attached.
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-11 08:10:04
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9120822AS rev.3.CLF
Running: 9rvd6sgn.exe; Driver: C:\DOCUME~1\PETERC~1\LOCALS~1\Temp\pxtdakog.sys
---- System - GMER 1.0.15 ----
SSDT spbi.sys ZwCreateKey [0xB9EB50E0]
SSDT spbi.sys ZwEnumerateKey [0xB9ECDDA4]
SSDT spbi.sys ZwEnumerateValueKey [0xB9ECE132]
SSDT spbi.sys ZwOpenKey [0xB9EB50C0]
SSDT spbi.sys ZwQueryKey [0xB9ECE20A]
SSDT spbi.sys ZwQueryValueKey [0xB9ECE08A]
SSDT spbi.sys ZwSetValueKey [0xB9ECE29C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB734C620]
INT 0x62 ? 8A6D8BF8
INT 0x63 ? 8A4DFBF8
INT 0x73 ? 8A4DFBF8
INT 0x74 ? 8A4DFBF8
INT 0x82 ? 8A6D8BF8
INT 0x83 ? 8A4DFBF8
INT 0x84 ? 8A4DFBF8
INT 0x94 ? 8A4DFBF8
INT 0xB4 ? 8A4DFBF8
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB4ABD1B1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB4ABD1DB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB4ABD145]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB4ABD171]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB4ABD205]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB4ABD1C5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB4ABD15B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB4ABD19D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB4ABD21B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB4ABD1EF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B4ABD1F3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP B4ABD1B5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B1FE6 7 Bytes JMP B4ABD209 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2DF4 5 Bytes JMP B4ABD21F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83CA 7 Bytes JMP B4ABD1C9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11EA 5 Bytes JMP B4ABD1DF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D2982 5 Bytes JMP B4ABD1A1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231EA 7 Bytes JMP B4ABD15F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C64 7 Bytes JMP B4ABD149 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E34 7 Bytes JMP B4ABD175 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? spbi.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8B6B360, 0x388D2D, 0xE8000020]
.text USBPORT.SYS!DllUnload B8B0A8AC 5 Bytes JMP 8A4DF1D8
.text aspvqz95.SYS B89C9386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text aspvqz95.SYS B89C93AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text aspvqz95.SYS B89C93C4 3 Bytes [00, 80, 02]
.text aspvqz95.SYS B89C93C9 1 Byte [30]
.text aspvqz95.SYS B89C93C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A10000
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10062
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A10051
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10036
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A10F83
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A10F94
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A1008E
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A1007D
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A10F10
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A10F21
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A10EFF
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A1001B
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A10FDB
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A10F52
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A10FAF
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A10FC0
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A1009F
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A00FC3
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A00F97
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A00FD4
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A00FE5
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A00054
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A0000A
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00A00039
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A00FB2
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009F0047
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!system 77C293C7 5 Bytes JMP 009F0FBC
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009F0011
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009F0FE3
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009F002C
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009F0000
.text C:\WINDOWS\system32\svchost.exe[312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006C000A
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0439000A
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 04390091
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 04390F9C
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 04390080
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0439006F
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0439004A
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 043900DA
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 043900BD
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 043900FF
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 04390F66
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 04390F4B
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 04390FCD
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0439001B
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 043900AC
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 04390FDE
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 04390FEF
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 04390F77
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 04380FE5
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 04380076
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0438002C
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0438001B
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 04380FAF
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0438000A
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0438005B
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 04380FD4
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 04370070
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!system 77C293C7 5 Bytes JMP 0437005F
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 04370FE5
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0437000C
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 04370044
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0437001D
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 02660FEF
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 02660FDE
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 0266000A
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 02660FB9
.text C:\WINDOWS\Explorer.EXE[1120] WS2_32.dll!socket 71AB4211 5 Bytes JMP 04360000
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE005B
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0F70
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE004A
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0F8D
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0FB2
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE008A
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE0F38
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE0EF1
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE0F16
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE00AF
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE002F
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0FDE
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE0F55
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FC3
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0014
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE0F27
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00660FA8
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00660036
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00660FB9
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00660FCA
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0066001B
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00660F79
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [86, 88]
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0066000A
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00650FA6
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!system 77C293C7 5 Bytes JMP 00650FB7
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00650FE3
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00650FD2
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0065001D
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00630000
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00630011
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00630022
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00630047
.text C:\WINDOWS\system32\svchost.exe[1272] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0F26
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE0F4B
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0F68
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0F79
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0FAF
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F04
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE004C
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0EDF
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE0078
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE0089
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE0F94
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE0F15
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE0067
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FD0FCA
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FD0040
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FD0025
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FD000A
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FD0F83
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FD0F94
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1D, 89]
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FD0FB9
I have windows XP
so my brother put a virus on my computer... again...
I accessed a hidden folder and McAfee immediately notified me that it deleted a file called "SecurityCheck.exe" from the folder I was looking at and said it was a trojan. I scanned my computer after that and found 2 weird generic files which were also designated as trojans...
I assume that these might come back so I am wondering if I can get help disinfecting my computer...
Do these trojans steal information??
GMER is copy/pasted, the rest of the logs are attached.
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-11 08:10:04
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9120822AS rev.3.CLF
Running: 9rvd6sgn.exe; Driver: C:\DOCUME~1\PETERC~1\LOCALS~1\Temp\pxtdakog.sys
---- System - GMER 1.0.15 ----
SSDT spbi.sys ZwCreateKey [0xB9EB50E0]
SSDT spbi.sys ZwEnumerateKey [0xB9ECDDA4]
SSDT spbi.sys ZwEnumerateValueKey [0xB9ECE132]
SSDT spbi.sys ZwOpenKey [0xB9EB50C0]
SSDT spbi.sys ZwQueryKey [0xB9ECE20A]
SSDT spbi.sys ZwQueryValueKey [0xB9ECE08A]
SSDT spbi.sys ZwSetValueKey [0xB9ECE29C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB734C620]
INT 0x62 ? 8A6D8BF8
INT 0x63 ? 8A4DFBF8
INT 0x73 ? 8A4DFBF8
INT 0x74 ? 8A4DFBF8
INT 0x82 ? 8A6D8BF8
INT 0x83 ? 8A4DFBF8
INT 0x84 ? 8A4DFBF8
INT 0x94 ? 8A4DFBF8
INT 0xB4 ? 8A4DFBF8
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB4ABD1B1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB4ABD1DB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB4ABD145]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB4ABD171]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB4ABD205]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB4ABD1C5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB4ABD15B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB4ABD19D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB4ABD21B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB4ABD1EF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B4ABD1F3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP B4ABD1B5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B1FE6 7 Bytes JMP B4ABD209 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2DF4 5 Bytes JMP B4ABD21F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83CA 7 Bytes JMP B4ABD1C9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11EA 5 Bytes JMP B4ABD1DF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D2982 5 Bytes JMP B4ABD1A1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231EA 7 Bytes JMP B4ABD15F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C64 7 Bytes JMP B4ABD149 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E34 7 Bytes JMP B4ABD175 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? spbi.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8B6B360, 0x388D2D, 0xE8000020]
.text USBPORT.SYS!DllUnload B8B0A8AC 5 Bytes JMP 8A4DF1D8
.text aspvqz95.SYS B89C9386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text aspvqz95.SYS B89C93AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text aspvqz95.SYS B89C93C4 3 Bytes [00, 80, 02]
.text aspvqz95.SYS B89C93C9 1 Byte [30]
.text aspvqz95.SYS B89C93C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A10000
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10062
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A10051
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10036
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A10F83
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A10F94
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A1008E
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A1007D
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A10F10
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A10F21
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A10EFF
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A1001B
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A10FDB
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A10F52
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A10FAF
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A10FC0
.text C:\WINDOWS\system32\svchost.exe[312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A1009F
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A00FC3
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A00F97
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A00FD4
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A00FE5
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A00054
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A0000A
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00A00039
.text C:\WINDOWS\system32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A00FB2
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009F0047
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!system 77C293C7 5 Bytes JMP 009F0FBC
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009F0011
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009F0FE3
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009F002C
.text C:\WINDOWS\system32\svchost.exe[312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009F0000
.text C:\WINDOWS\system32\svchost.exe[312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006C000A
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0439000A
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 04390091
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 04390F9C
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 04390080
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0439006F
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0439004A
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 043900DA
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 043900BD
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 043900FF
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 04390F66
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 04390F4B
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 04390FCD
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0439001B
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 043900AC
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 04390FDE
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 04390FEF
.text C:\WINDOWS\Explorer.EXE[1120] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 04390F77
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 04380FE5
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 04380076
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0438002C
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0438001B
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 04380FAF
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0438000A
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0438005B
.text C:\WINDOWS\Explorer.EXE[1120] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 04380FD4
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 04370070
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!system 77C293C7 5 Bytes JMP 0437005F
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 04370FE5
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0437000C
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 04370044
.text C:\WINDOWS\Explorer.EXE[1120] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0437001D
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 02660FEF
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 02660FDE
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 0266000A
.text C:\WINDOWS\Explorer.EXE[1120] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 02660FB9
.text C:\WINDOWS\Explorer.EXE[1120] WS2_32.dll!socket 71AB4211 5 Bytes JMP 04360000
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE005B
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0F70
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE004A
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0F8D
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0FB2
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE008A
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE0F38
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE0EF1
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE0F16
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE00AF
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE002F
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0FDE
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE0F55
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FC3
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0014
.text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE0F27
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00660FA8
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00660036
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00660FB9
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00660FCA
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0066001B
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00660F79
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [86, 88]
.text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0066000A
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00650FA6
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!system 77C293C7 5 Bytes JMP 00650FB7
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00650FE3
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00650FD2
.text C:\WINDOWS\system32\svchost.exe[1272] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0065001D
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00630000
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00630011
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00630022
.text C:\WINDOWS\system32\svchost.exe[1272] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00630047
.text C:\WINDOWS\system32\svchost.exe[1272] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0F26
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE0F4B
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0F68
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0F79
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0FAF
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F04
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE004C
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0EDF
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE0078
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE0089
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE0F94
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE0F15
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\services.exe[1372] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE0067
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FD0FCA
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FD0040
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FD0025
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FD000A
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FD0F83
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FD0F94
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1D, 89]
.text C:\WINDOWS\system32\services.exe[1372] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FD0FB9