GMER log
GMER log:
----------------
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-11-18 07:38:37
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e TOSHIBA_MK8032GSX rev.AS111G
Running: vt1fwi92.exe; Driver: C:\DOCUME~1\KAUSHI~1\LOCALS~1\Temp\fxlirpoc.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB9E90DB0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB9E90DC4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB9E90DF0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB9E90E46]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB9E90D9C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9E90D74]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9E90D88]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB9E90DDA]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB9E90E1C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB9E90E06]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB9E90E70]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB9E90E5C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB9E90E30]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 8050225C 7 Bytes JMP B9E90E34 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805A74F0 7 Bytes JMP B9E90E4A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A8306 5 Bytes JMP B9E90E60 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetSecurityObject 805B6040 5 Bytes JMP B9E90E20 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805C1316 5 Bytes JMP B9E90D78 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805C15A2 5 Bytes JMP B9E90D8C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805C8CAA 5 Bytes JMP B9E90E74 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 806188B6 7 Bytes JMP B9E90E0A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80619D66 7 Bytes JMP B9E90DDE mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 8061A344 5 Bytes JMP B9E90DB4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8061A7E0 7 Bytes JMP B9E90DC8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8061A9B0 7 Bytes JMP B9E90DF4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 8061B722 5 Bytes JMP B9E90DA0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[264] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00AD0000
.text C:\WINDOWS\Explorer.EXE[264] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00AD0FC0
.text C:\WINDOWS\Explorer.EXE[264] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AD0FDB
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01AF0FEF
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01AF0F5A
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01AF0F75
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01AF0F86
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01AF0F97
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01AF0FC3
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01AF007D
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01AF0F35
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01AF0EE4
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01AF0EFF
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01AF0098
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01AF0FA8
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01AF0014
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01AF0060
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01AF0FD4
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01AF0025
.text C:\WINDOWS\Explorer.EXE[264] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01AF0F10
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01AE002F
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01AE0065
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01AE000A
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01AE0FDE
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01AE0FA8
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01AE0FEF
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01AE0FC3
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [CE, 89]
.text C:\WINDOWS\Explorer.EXE[264] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01AE0040
.text C:\WINDOWS\Explorer.EXE[264] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 014B0FD4
.text C:\WINDOWS\Explorer.EXE[264] msvcrt.dll!system 77C293C7 5 Bytes JMP 014B0069
.text C:\WINDOWS\Explorer.EXE[264] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 014B0029
.text C:\WINDOWS\Explorer.EXE[264] msvcrt.dll!_open 77C2F566 5 Bytes JMP 014B0FEF
.text C:\WINDOWS\Explorer.EXE[264] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 014B0044
.text C:\WINDOWS\Explorer.EXE[264] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 014B000C
.text C:\WINDOWS\Explorer.EXE[264] WININET.dll!InternetOpenW 771BAF49 5 Bytes JMP 013E0FEF
.text C:\WINDOWS\Explorer.EXE[264] WININET.dll!InternetOpenA 771C5796 5 Bytes JMP 013E000A
.text C:\WINDOWS\Explorer.EXE[264] WININET.dll!InternetOpenUrlA 771C5A62 5 Bytes JMP 013E0031
.text C:\WINDOWS\Explorer.EXE[264] WININET.dll!InternetOpenUrlW 771D5BB2 5 Bytes JMP 013E0042
.text C:\WINDOWS\Explorer.EXE[264] WS2_32.dll!socket 71AB4211 5 Bytes JMP 012C0FEF
.text C:\WINDOWS\system32\svchost.exe[292] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00740000
.text C:\WINDOWS\system32\svchost.exe[292] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00740FCA
.text C:\WINDOWS\system32\svchost.exe[292] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00740FE5
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0078000A
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0078008A
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00780F8B
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00780F9C
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0078005B
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00780FD4
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00780F69
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007800B1
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007800EE
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007800DD
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 007800FF
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00780FB9
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00780025
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00780F7A
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00780FE5
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00780036
.text C:\WINDOWS\system32\svchost.exe[292] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 007800CC
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00770022
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0077005F
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00770011
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00770000
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00770F98
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00770FEF
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00770044
.text C:\WINDOWS\system32\svchost.exe[292] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00770033
.text C:\WINDOWS\system32\svchost.exe[292] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00760FB4
.text C:\WINDOWS\system32\svchost.exe[292] msvcrt.dll!system 77C293C7 5 Bytes JMP 0076003F
.text C:\WINDOWS\system32\svchost.exe[292] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0076002E
.text C:\WINDOWS\system32\svchost.exe[292] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00760000
.text C:\WINDOWS\system32\svchost.exe[292] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00760FD9
.text C:\WINDOWS\system32\svchost.exe[292] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0076001D
.text C:\WINDOWS\system32\svchost.exe[292] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00750FEF
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[384] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[384] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[600] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00990FEF
.text C:\WINDOWS\system32\svchost.exe[600] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\svchost.exe[600] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00990FD4
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A10FEF
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10084
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A10069
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10F9B
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A10058
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A10036
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A100C1
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A100B0
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A10F4A
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A100ED
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A10F39
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A10047
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A10FD4
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A1009F
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A1001B
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A1000A
.text C:\WINDOWS\system32\svchost.exe[600] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A100DC
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009C0036
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009C0F8D
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009C001B
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009C000A
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009C0FA8
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009C0FEF
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 009C0FB9
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [BC, 88]
.text C:\WINDOWS\system32\svchost.exe[600] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009C0FCA
.text C:\WINDOWS\system32\svchost.exe[600] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009B0FA6
.text C:\WINDOWS\system32\svchost.exe[600] msvcrt.dll!system 77C293C7 5 Bytes JMP 009B0FB7
.text C:\WINDOWS\system32\svchost.exe[600] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009B001D
.text C:\WINDOWS\system32\svchost.exe[600] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009B000C
.text C:\WINDOWS\system32\svchost.exe[600] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009B0FC8
.text C:\WINDOWS\system32\svchost.exe[600] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009B0FEF
.text C:\WINDOWS\system32\svchost.exe[600] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009A0FEF
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 02B70FEF
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 02B70FD4
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 02B7000A
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02BB0FEF
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02BB0F69
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02BB005E
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02BB0F84
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02BB0FA1
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02BB0FCD
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02BB0094
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02BB0F4E
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02BB0F16
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02BB00AF
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02BB00CA
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02BB0FB2
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02BB0014
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02BB0079
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02BB002F
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02BB0FDE
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02BB0F31
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02BA0FB9
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegCreateKeyExW 77DD776C 5 Bytes JMP 02BA0F97
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegOpenKeyExA 77DD7852 5 Bytes JMP 02BA0FCA
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegOpenKeyW 77DD7946 5 Bytes JMP 02BA0FDB
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02BA004A
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02BA0000
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegCreateKeyW 77DFBA55 2 Bytes JMP 02BA0FA8
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegCreateKeyW + 3 77DFBA58 2 Bytes [DA, 8A]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] ADVAPI32.DLL!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02BA0025
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] MSVCRT.DLL!_wsystem 77C2931E 5 Bytes JMP 02B90F9C
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] MSVCRT.DLL!system 77C293C7 5 Bytes JMP 02B9001D
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] MSVCRT.DLL!_creat 77C2D40F 5 Bytes JMP 02B90FC1
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] MSVCRT.DLL!_open 77C2F566 5 Bytes JMP 02B90FEF
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] MSVCRT.DLL!_wcreat 77C2FC9B 5 Bytes JMP 02B9000C
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] MSVCRT.DLL!_wopen 77C30055 5 Bytes JMP 02B90FDE
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[644] WS2_32.dll!socket 02354211 5 Bytes JMP 02B80000
.text C:\WINDOWS\system32\svchost.exe[1284] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00A40FEF
.text C:\WINDOWS\system32\svchost.exe[1284] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A40FC3
.text C:\WINDOWS\system32\svchost.exe[1284] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A40FD4
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A90FE5
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A9005B
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A9004A
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A90F70
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A90F8D
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A90025
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A90087
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A90F3F
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A90EF8
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A90F13
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A900AC
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A90F9E
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A90FCA
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A90076
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A90FAF
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A90000
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A90F24
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A80FC3
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A8002F
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A80FD4
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A80FEF
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A80F7C
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A8000A
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A80F8D
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C8, 88]
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A80FB2
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A70F92
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A7001D
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A70FC8
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A70FEF
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A70FB7
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A70000
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenW 771BAF49 5 Bytes JMP 00A60011
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenA 771C5796 5 Bytes JMP 00A60000
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenUrlA 771C5A62 5 Bytes JMP 00A6002E
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenUrlW 771D5BB2 5 Bytes JMP 00A6003F
.text C:\WINDOWS\system32\svchost.exe[1284] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A50FEF
.text C:\WINDOWS\system32\services.exe[1440] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[1440] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00040FEF
.text C:\WINDOWS\system32\services.exe[1440] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0004001B
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00770000
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0077006E
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00770F79
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00770053
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00770F8A
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00770FB6
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00770F39
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0077008B
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00770F28
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007700C1
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 007700E6
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00770F9B
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0077001B
.text C:\WINDOWS\system32\services.exe[1440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00770F5E