GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-02-23 22:15:13
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200AAKS-75L9A0 rev.01.03E01
Running: 7pu3g73d.exe; Driver: C:\Users\Steve\AppData\Local\Temp\ugloypob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8D439FC4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8D43C456]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8D43C4AE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8D43C5C4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8D43C3AC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8D43C4FE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8D43C400]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8D43C572]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8D439FE8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8D439DB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8D43A00C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8D43C9BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8D43AAA4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8D43C486]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8D43C4D6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8D43C5EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8D43C3D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8D43C53E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8D43C42E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8D43C59C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8D43A96A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8D43A030]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8D43A054]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8D439E0C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8D439F48]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8D439F24]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8D439F6C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x8D537640]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8D43A078]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8D5C07A2]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 828C7890 4 Bytes [C4, 9F, 43, 8D]
.text ntkrnlpa.exe!KeSetEvent + 1D1 828C7954 8 Bytes [56, C4, 43, 8D, AE, C4, 43, ...] {PUSH ESI; LES EAX, DWORD [EBX-0x73]; SCASB ; LES EAX, DWORD [EBX-0x73]}
.text ntkrnlpa.exe!KeSetEvent + 1DD 828C7960 4 Bytes [C4, C5, 43, 8D]
.text ntkrnlpa.exe!KeSetEvent + 1F5 828C7978 4 Bytes [AC, C3, 43, 8D]
.text ntkrnlpa.exe!KeSetEvent + 215 828C7998 8 Bytes [FE, C4, 43, 8D, 00, C4, 43, ...] {INC AH; INC EBX; LEA EAX, [EAX]; LES EAX, DWORD [EBX-0x73]}
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 829F25C7 5 Bytes JMP 8D5BD69C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 82A4B4F3 5 Bytes JMP 8D5BF15C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82A54E18 4 Bytes CALL 8D43B025 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82A58A8C 4 Bytes CALL 8D43B03B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82AACDAE 7 Bytes JMP 8D5C07A6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text win32k.sys!EngCreateRectRgn + 4537 97ABFC90 5 Bytes JMP 8D43D0D6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 8C03 97AE2407 5 Bytes JMP 8D43C9F2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 30F1 97AEEA84 5 Bytes JMP 8D43CF90 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 455C 97AEFEEF 5 Bytes JMP 8D43CB9A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 119C6 97B09A25 5 Bytes JMP 8D43CDE6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 11A1A 97B09A79 5 Bytes JMP 8D43CFBC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 60DE 97B33371 5 Bytes JMP 8D43CABE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 4D3A 97B39CA9 5 Bytes JMP 8D43CC0A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStrokePath + 5FF 97B46FFC 5 Bytes JMP 8D43CAD6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_vEnumStart + 4728 97B76B49 5 Bytes JMP 8D43CB56 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + E80 97B950A6 5 Bytes JMP 8D43CD14 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_bEnum + 248 97B9A902 5 Bytes JMP 8D43CC6E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + A0F 97BBD707 5 Bytes JMP 8D43CCA4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + D23F 97BC9F37 5 Bytes JMP 8D43CD4E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? C:\Users\Steve\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
? C:\Users\Steve\AppData\Local\Temp\aswMBR.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\wuauclt.exe[276] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000601F8
.text C:\Windows\system32\wuauclt.exe[276] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000603FC
.text C:\Windows\system32\wuauclt.exe[276] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\wuauclt.exe[276] USER32.dll!SetWindowsHookExA 76F06322 5 Bytes JMP 00070600
.text C:\Windows\system32\wuauclt.exe[276] USER32.dll!SetWindowsHookExW 76F087AD 5 Bytes JMP 00070804
.text C:\Windows\system32\wuauclt.exe[276] USER32.dll!UnhookWindowsHookEx 76F098DB 5 Bytes JMP 00070A08
.text C:\Windows\system32\wuauclt.exe[276] USER32.dll!SetWinEventHook 76F09F3A 5 Bytes JMP 000701F8
.text C:\Windows\system32\wuauclt.exe[276] USER32.dll!UnhookWinEvent 76F0C06F 5 Bytes JMP 000703FC
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\wuauclt.exe[276] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[468] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[468] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[468] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[468] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[468] USER32.dll!SetWindowsHookExA 76F06322 5 Bytes JMP 00BF0600
.text C:\Windows\system32\svchost.exe[468] USER32.dll!SetWindowsHookExW 76F087AD 5 Bytes JMP 00BF0804
.text C:\Windows\system32\svchost.exe[468] USER32.dll!UnhookWindowsHookEx 76F098DB 5 Bytes JMP 00BF0A08
.text C:\Windows\system32\svchost.exe[468] USER32.dll!SetWinEventHook 76F09F3A 5 Bytes JMP 00BF01F8
.text C:\Windows\system32\svchost.exe[468] USER32.dll!UnhookWinEvent 76F0C06F 5 Bytes JMP 00BF03FC
.text C:\Windows\System32\svchost.exe[472] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[472] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[472] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[472] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000701F8
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000501F8
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000503FC
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] USER32.dll!SetWindowsHookExA 76F06322 5 Bytes JMP 00070600
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] USER32.dll!SetWindowsHookExW 76F087AD 5 Bytes JMP 00070804
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] USER32.dll!UnhookWindowsHookEx 76F098DB 5 Bytes JMP 00070A08
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] USER32.dll!SetWinEventHook 76F09F3A 5 Bytes JMP 000701F8
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] USER32.dll!UnhookWinEvent 76F0C06F 5 Bytes JMP 000703FC
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000803FC
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00080600
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00081014
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00080804
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00080A08
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00080C0C
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00080E10
.text C:\Program Files\SUPERAntiSpyware\SASCORE.EXE[516] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\csrss.exe[528] KERNEL32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\wininit.exe[572] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[572] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[572] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[572] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[572] USER32.dll!SetWindowsHookExA 76F06322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[572] USER32.dll!SetWindowsHookExW 76F087AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[572] USER32.dll!UnhookWindowsHookEx 76F098DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[572] USER32.dll!SetWinEventHook 76F09F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[572] USER32.dll!UnhookWinEvent 76F0C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[580] KERNEL32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[612] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[612] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[612] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\winlogon.exe[612] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\winlogon.exe[612] USER32.dll!SetWindowsHookExA 76F06322 5 Bytes JMP 000A0600
.text C:\Windows\system32\winlogon.exe[612] USER32.dll!SetWindowsHookExW 76F087AD 5 Bytes JMP 000A0804
.text C:\Windows\system32\winlogon.exe[612] USER32.dll!UnhookWindowsHookEx 76F098DB 5 Bytes JMP 000A0A08
.text C:\Windows\system32\winlogon.exe[612] USER32.dll!SetWinEventHook 76F09F3A 5 Bytes JMP 000A01F8
.text C:\Windows\system32\winlogon.exe[612] USER32.dll!UnhookWinEvent 76F0C06F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\services.exe[656] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[656] ntdll.dll!LdrUnloadDll 7756B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[656] kernel32.dll!GetBinaryTypeW + 70 76D12247 1 Byte [62]
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!CreateServiceW 76C39EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!DeleteService 76C3A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!SetServiceObjectSecurity 76C76CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!ChangeServiceConfigA 76C76DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!ChangeServiceConfigW 76C76F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!ChangeServiceConfig2A 76C77099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!ChangeServiceConfig2W 76C771E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!CreateServiceA 76C772A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[656] USER32.dll!SetWindowsHookExA 76F06322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[656] USER32.dll!SetWindowsHookExW 76F087AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[656] USER32.dll!UnhookWindowsHookEx 76F098DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[656] USER32.dll!SetWinEventHook 76F09F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[656] USER32.dll!UnhookWinEvent 76F0C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[672] ntdll.dll!LdrLoadDll 775593A8 5 Bytes JMP 000501F8