Beachmtn01
Posts: 14 +0
I have begun the eight step process and have the requested logs below:
Malwarebytes Anti-Malware log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5999
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/12/2011 11:43:00 PM
mbam-log-2011-03-12 (23-43-00).txt
Scan type: Quick scan
Objects scanned: 173342
Time elapsed: 6 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-13 13:03:12
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2 ST325082 rev.3.AD
Running: n8bxlbf4.exe; Driver: C:\DOCUME~1\Jesse\LOCALS~1\Temp\pxtdipow.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB9E100E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB9E100F4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB9E10120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB9E10176]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB9E100CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9E100A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9E100B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB9E1010A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB9E1014C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB9E10136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB9E101A0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB9E1018C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB9E10160]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B9E10164 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B203A 7 Bytes JMP B9E1017A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E48 5 Bytes JMP B9E10190 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetSecurityObject 805C062E 5 Bytes JMP B9E10150 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB440 5 Bytes JMP B9E100A8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6CC 5 Bytes JMP B9E100BC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29E2 5 Bytes JMP B9E101A4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80622662 7 Bytes JMP B9E1013A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80623B12 7 Bytes JMP B9E1010E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806240F0 5 Bytes JMP B9E100E4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8062458C 7 Bytes JMP B9E100F8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8062475C 7 Bytes JMP B9E10124 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 806254CE 5 Bytes JMP B9E100D0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[440] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00CE0FE5
.text C:\WINDOWS\system32\svchost.exe[440] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00CE000A
.text C:\WINDOWS\system32\svchost.exe[440] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CD000A
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CD0084
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CD0073
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CD0062
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CD0FAF
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CD0FDB
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CD00C3
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CD00B2
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CD0F2A
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CD0F3B
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CD0F19
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CD0FCA
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CD001B
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CD0095
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CD0047
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CD002C
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CD0F60
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 003A0FB9
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 003A003D
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 003A000A
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 003A0FD4
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 003A002C
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 003A0FEF
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 003A001B
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 003A0F94
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00390033
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!system 77C293C7 5 Bytes JMP 00390022
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00390FBC
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00390FE3
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00390011
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00390000
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00370FEF
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00370000
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00370FC0
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 00370011
.text C:\WINDOWS\system32\svchost.exe[440] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00380FE5
.text C:\WINDOWS\Explorer.EXE[612] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 01730FEF
.text C:\WINDOWS\Explorer.EXE[612] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0173002F
.text C:\WINDOWS\Explorer.EXE[612] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0173000A
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01700FEF
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01700F72
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01700F8D
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01700F9E
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0170005B
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01700FC3
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 017000AE
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0170009D
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01700F37
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 017000DA
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01700F1C
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0170004A
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01700014
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0170008C
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01700FD4
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01700025
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 017000C9
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 016F001E
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 016F0054
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 016F0FC3
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 016F0FDE
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 016F0F97
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 016F0FEF
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 016F0043
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 016F0FB2
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02690FAD
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!system 77C293C7 5 Bytes JMP 02690042
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0269001D
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02690000
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02690FC8
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02690FE3
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 02610000
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 02610FDB
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 02610011
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 02610FC0
.text C:\WINDOWS\Explorer.EXE[612] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02680000
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00920000
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00920FD4
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00920FEF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00910FEF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0091004A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0091002F
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00910F57
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00910F72
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00910F9E
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00910F2E
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00910076
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00910F09
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009100A2
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00910EEE
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00910F83
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00910FDE
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0091005B
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00910FAF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0091000A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00910091
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FD0047
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FD0FB6
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FD002C
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FD001B
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FD0FD1
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FD0000
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00FD0073
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FD0058
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00940FB2
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!system 77C293C7 5 Bytes JMP 00940033
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00940018
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00940FEF
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00940FC3
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00940FDE
.text C:\WINDOWS\system32\services.exe[1128] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00930000
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00F60000
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00F6001B
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F60FE5
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E800BD
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E800A2
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E80091
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E80FD4
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E8005B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E80FA3
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E800EB
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E80121
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E80F88
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E80F77
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E80076
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E80014
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E800CE
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E8004A
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E80025
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E80106
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C50FB2
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C50F86
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C50FCD
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C50FDE
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C5004D
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C50FEF
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C50FA1
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [E5, 88] {IN EAX, 0x88}
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C5001E
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C40027
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C40016
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C40FB7
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C40FE3
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C40F9C
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C40FD2
.text C:\WINDOWS\system32\lsass.exe[1140] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C30000
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00DC0000
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DC0FDB
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DC0011
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DB0FEF
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DB0F55
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DB0F7A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DB0054
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DB0043
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DB001E
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DB0F0C
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DB0F1D
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DB009B
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DB008A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00DB00B6
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00DB0F97
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00DB0FDE
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00DB0F44
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00DB0FB2
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00DB0FCD
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00DB006F
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DF007D
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DF0FDE
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DF0062
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DF0051
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DF0036
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0FAF
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0044
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FDE
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0033
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0FEF
.text C:\WINDOWS\system32\svchost.exe[1376] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00FF0FB9
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FF0FCA
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE007C
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE006B
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0050
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0F91
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0022
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F60
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE00A8
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0F3B
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE00D4
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE00E5
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE0033
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE008D
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE00C3
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 010F003D
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 010F0FB6
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 010F002C
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 010F001B
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 010F0FC7
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 010F000A
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 010F0073
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 010F0058
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 010E0025
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!system 77C293C7 5 Bytes JMP 010E0F9A
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 010E0FC6
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_open 77C2F566 5 Bytes JMP 010E0FE3
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 010E0FB5
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 010E0000
.text C:\WINDOWS\system32\svchost.exe[1472] WS2_32.dll!socket 71AB4211 5 Bytes JMP 010D0FE5
.text C:\WINDOWS\system32\svchost.exe[1576] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00C00000
.text C:\WINDOWS\system32\svchost.exe[1576] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00C00FE5
.text C:\WINDOWS\system32\svchost.exe[1576] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C00011
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0F6F
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF005A
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0049
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0F80
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF002C
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF00A4
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0089
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF0F1C
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!
Malwarebytes Anti-Malware log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5999
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/12/2011 11:43:00 PM
mbam-log-2011-03-12 (23-43-00).txt
Scan type: Quick scan
Objects scanned: 173342
Time elapsed: 6 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-13 13:03:12
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2 ST325082 rev.3.AD
Running: n8bxlbf4.exe; Driver: C:\DOCUME~1\Jesse\LOCALS~1\Temp\pxtdipow.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB9E100E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB9E100F4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB9E10120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB9E10176]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB9E100CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9E100A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9E100B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB9E1010A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB9E1014C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB9E10136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB9E101A0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB9E1018C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB9E10160]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B9E10164 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B203A 7 Bytes JMP B9E1017A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E48 5 Bytes JMP B9E10190 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetSecurityObject 805C062E 5 Bytes JMP B9E10150 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB440 5 Bytes JMP B9E100A8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6CC 5 Bytes JMP B9E100BC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29E2 5 Bytes JMP B9E101A4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80622662 7 Bytes JMP B9E1013A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80623B12 7 Bytes JMP B9E1010E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806240F0 5 Bytes JMP B9E100E4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8062458C 7 Bytes JMP B9E100F8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8062475C 7 Bytes JMP B9E10124 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 806254CE 5 Bytes JMP B9E100D0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[440] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00CE0FE5
.text C:\WINDOWS\system32\svchost.exe[440] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00CE000A
.text C:\WINDOWS\system32\svchost.exe[440] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CD000A
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CD0084
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CD0073
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CD0062
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CD0FAF
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CD0FDB
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CD00C3
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CD00B2
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CD0F2A
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CD0F3B
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CD0F19
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CD0FCA
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CD001B
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CD0095
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CD0047
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CD002C
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CD0F60
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 003A0FB9
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 003A003D
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 003A000A
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 003A0FD4
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 003A002C
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 003A0FEF
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 003A001B
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 003A0F94
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00390033
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!system 77C293C7 5 Bytes JMP 00390022
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00390FBC
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00390FE3
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00390011
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00390000
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00370FEF
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00370000
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00370FC0
.text C:\WINDOWS\system32\svchost.exe[440] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 00370011
.text C:\WINDOWS\system32\svchost.exe[440] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00380FE5
.text C:\WINDOWS\Explorer.EXE[612] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 01730FEF
.text C:\WINDOWS\Explorer.EXE[612] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0173002F
.text C:\WINDOWS\Explorer.EXE[612] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0173000A
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01700FEF
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01700F72
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01700F8D
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01700F9E
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0170005B
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01700FC3
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 017000AE
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0170009D
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01700F37
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 017000DA
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01700F1C
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0170004A
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01700014
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0170008C
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01700FD4
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01700025
.text C:\WINDOWS\Explorer.EXE[612] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 017000C9
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 016F001E
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 016F0054
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 016F0FC3
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 016F0FDE
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 016F0F97
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 016F0FEF
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 016F0043
.text C:\WINDOWS\Explorer.EXE[612] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 016F0FB2
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02690FAD
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!system 77C293C7 5 Bytes JMP 02690042
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0269001D
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02690000
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02690FC8
.text C:\WINDOWS\Explorer.EXE[612] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02690FE3
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 02610000
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 02610FDB
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 02610011
.text C:\WINDOWS\Explorer.EXE[612] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 02610FC0
.text C:\WINDOWS\Explorer.EXE[612] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02680000
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00920000
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00920FD4
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00920FEF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00910FEF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0091004A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0091002F
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00910F57
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00910F72
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00910F9E
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00910F2E
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00910076
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00910F09
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009100A2
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00910EEE
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00910F83
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00910FDE
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0091005B
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00910FAF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0091000A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00910091
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FD0047
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FD0FB6
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FD002C
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FD001B
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FD0FD1
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FD0000
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00FD0073
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FD0058
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00940FB2
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!system 77C293C7 5 Bytes JMP 00940033
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00940018
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00940FEF
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00940FC3
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00940FDE
.text C:\WINDOWS\system32\services.exe[1128] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00930000
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00F60000
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00F6001B
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F60FE5
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E800BD
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E800A2
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E80091
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E80FD4
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E8005B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E80FA3
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E800EB
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E80121
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E80F88
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E80F77
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E80076
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E80014
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E800CE
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E8004A
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E80025
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E80106
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C50FB2
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C50F86
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C50FCD
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C50FDE
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C5004D
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C50FEF
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C50FA1
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [E5, 88] {IN EAX, 0x88}
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C5001E
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C40027
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C40016
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C40FB7
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C40FE3
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C40F9C
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C40FD2
.text C:\WINDOWS\system32\lsass.exe[1140] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C30000
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00DC0000
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DC0FDB
.text C:\WINDOWS\system32\svchost.exe[1376] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DC0011
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DB0FEF
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DB0F55
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DB0F7A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DB0054
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DB0043
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DB001E
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DB0F0C
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DB0F1D
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DB009B
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DB008A
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00DB00B6
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00DB0F97
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00DB0FDE
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00DB0F44
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00DB0FB2
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00DB0FCD
.text C:\WINDOWS\system32\svchost.exe[1376] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00DB006F
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DF007D
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DF0FDE
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DF0062
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DF0051
.text C:\WINDOWS\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DF0036
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0FAF
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0044
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FDE
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0033
.text C:\WINDOWS\system32\svchost.exe[1376] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0FEF
.text C:\WINDOWS\system32\svchost.exe[1376] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00FF0FB9
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FF0FCA
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE007C
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE006B
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0050
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0F91
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0022
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F60
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE00A8
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0F3B
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE00D4
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE00E5
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE0033
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE008D
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE00C3
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 010F003D
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 010F0FB6
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 010F002C
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 010F001B
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 010F0FC7
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 010F000A
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 010F0073
.text C:\WINDOWS\system32\svchost.exe[1472] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 010F0058
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 010E0025
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!system 77C293C7 5 Bytes JMP 010E0F9A
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 010E0FC6
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_open 77C2F566 5 Bytes JMP 010E0FE3
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 010E0FB5
.text C:\WINDOWS\system32\svchost.exe[1472] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 010E0000
.text C:\WINDOWS\system32\svchost.exe[1472] WS2_32.dll!socket 71AB4211 5 Bytes JMP 010D0FE5
.text C:\WINDOWS\system32\svchost.exe[1576] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00C00000
.text C:\WINDOWS\system32\svchost.exe[1576] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00C00FE5
.text C:\WINDOWS\system32\svchost.exe[1576] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C00011
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0F6F
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF005A
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0049
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0F80
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF002C
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF00A4
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0089
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF0F1C
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!