Results of system analysis

Kaspersky Virus Removal Tool 2010 9.0.0.722 (database released 24/06/2011; 18:47)

List of processes

File namePIDDescriptionCopyrightMD5Information
c:\windows\explorer.exe
Script: Quarantine, Delete, BC delete, Terminate
360Windows Explorer© Microsoft Corporation. All rights reserved.??2553.50 kb, rsAh,
created: 5/19/2011 4:36:27 PM,
modified: 2/26/2011 1:33:07 AM
Command line:
C:\Windows\Explorer.EXE
c:\program files\htc home 1.10\htchome.exe
Script: Quarantine, Delete, BC delete, Terminate
2640HTC HomeCopyright © Stealth 2010??327.50 kb, rsAh,
created: 6/10/2011 12:47:50 PM,
modified: 10/13/2010 12:43:54 PM
Command line:
"C:\Program Files\HTC Home 1.10\HTCHome.exe"
c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
5232Internet Explorer© Microsoft Corporation. All rights reserved.??730.80 kb, rsAh,
created: 5/20/2011 11:21:16 PM,
modified: 5/20/2011 11:21:16 PM
Command line:
"C:\Program Files\Internet Explorer\iexplore.exe"
c:\program files\malwarebytes' anti-malware\mbamgui.exe
Script: Quarantine, Delete, BC delete, Terminate
2508Malwarebytes' Anti-Malware© Malwarebytes Corporation. All rights reserved.??439.05 kb, rsAh,
created: 6/19/2011 11:14:33 PM,
modified: 5/29/2011 9:11:28 AM
Command line:
"C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
c:\program files\windows live\mesh\moe.exe
Script: Quarantine, Delete, BC delete, Terminate
2856Mesh Operating EnvironmentCopyright (c) Microsoft Corporation. All rights reserved.??69.84 kb, rsAh,
created: 10/19/2010 5:06:01 PM,
modified: 10/19/2010 5:06:01 PM
Command line:
"C:\Program Files\Windows Live\Mesh\MOE.exe" "Global\MOE_STARTUP_COMPLETE_146d973f-e241-434d-93ae-2bf832cd1640_Manan" "Global\MOE_SHUTDOWN_146d973f-e241-434d-93ae-2bf832cd1640_Manan"
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
Script: Quarantine, Delete, BC delete, Terminate
2712PresentationFontCache.exe© Microsoft Corporation. All rights reserved.??41.85 kb, rsAh,
created: 7/13/2009 8:35:50 PM,
modified: 6/10/2009 5:14:51 PM
Command line:
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\synaptics\syntp\syntpenh.exe
Script: Quarantine, Delete, BC delete, Terminate
2444Synaptics TouchPad EnhancementsCopyright (C) Synaptics, Inc. 1996-2008??1021.29 kb, rsAh,
created: 3/28/2008 2:05:00 AM,
modified: 3/28/2008 2:05:00 AM
Command line:
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
c:\program files\windows live\mesh\wlsync.exe
Script: Quarantine, Delete, BC delete, Terminate
2596Windows Live Mesh© Microsoft Corporation. All rights reserved.??1414.84 kb, rsAh,
created: 9/23/2010 1:19:02 AM,
modified: 9/23/2010 1:19:02 AM
Command line:
"C:\Program Files\Windows Live\Mesh\WLSync.exe" /background
Detected:51, recognized as trusted 51
Module nameHandleDescriptionCopyrightMD5Used by processes
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\e7b5050c2c315562d740c4b9535cf5ce\PresentationCore.ni.dll
Script: Quarantine, Delete, BC delete
1706688512PresentationCore.dll© Microsoft Corporation. All rights reserved.--2640, 2712
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\29c7c077fc7c8c95e5bef098e1201b10\PresentationFontCache.ni.exe
Script: Quarantine, Delete, BC delete
1680408576PresentationFontCache.exe© Microsoft Corporation. All rights reserved.--2712
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7114c629020f6bba198a954e4794c979\PresentationFramework.ni.dll
Script: Quarantine, Delete, BC delete
1692336128PresentationFramework.dll© Microsoft Corporation. All rights reserved.--2640
C:\Windows\system32\certvert.dll
Script: Quarantine, Delete, BC delete
268435456 Copyright (C) 2000--360, 2640, 5232, 2508, 2856, 2444, 2596
Modules detected:649, recognized as trusted 645

Kernel Space Modules Viewer

ModuleBase addressSize in memoryDescriptionManufacturer
C:\Windows\System32\Drivers\dump_dumpata.sys
Script: Quarantine, Delete, BC delete
94B0100000B000 (45056)
C:\Windows\System32\Drivers\dump_dumpfve.sys
Script: Quarantine, Delete, BC delete
94B16000011000 (69632)
C:\Windows\System32\Drivers\dump_msahci.sys
Script: Quarantine, Delete, BC delete
94B0C00000A000 (40960)
C:\Windows\System32\Drivers\spoq.sys
Script: Quarantine, Delete, BC delete
888940000F3000 (995328)
Modules detected - 198, recognized as trusted - 194

Services

ServiceDescriptionStatusFileGroupDependencies
Detected - 159, recognized as trusted - 159

Drivers

ServiceDescriptionStatusFileGroupDependencies
sptd
Driver: Unload, Delete, Disable
sptdRunningC:\Windows\System32\Drivers\sptd.sys
Script: Quarantine, Delete, BC delete
Boot Bus Extender 
catchme
Driver: Unload, Delete, Disable
catchmeNot startedC:\Users\Manan\AppData\Local\Temp\catchme.sys
Script: Quarantine, Delete, BC delete
Base 
nmwcd
Driver: Unload, Delete, Disable
Nokia USB Phone ParentNot startedC:\Windows\system32\drivers\ccdcmb.sys
Script: Quarantine, Delete, BC delete
Extended Base 
nmwcdc
Driver: Unload, Delete, Disable
Nokia USB GenericNot startedC:\Windows\system32\drivers\ccdcmbo.sys
Script: Quarantine, Delete, BC delete
  
pccsmcfd
Driver: Unload, Delete, Disable
PCCS Mode Change Filter DriverNot startedC:\Windows\system32\DRIVERS\pccsmcfd.sys
Script: Quarantine, Delete, BC delete
  
upperdev
Driver: Unload, Delete, Disable
upperdevNot startedC:\Windows\system32\DRIVERS\usbser_lowerflt.sys
Script: Quarantine, Delete, BC delete
  
UsbserFilt
Driver: Unload, Delete, Disable
UsbserFiltNot startedC:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
Script: Quarantine, Delete, BC delete
  
Detected - 265, recognized as trusted - 258

Autoruns

File nameStatusStartup methodDescription
C:\Program Files\Hewlett-Packard\HP-MPI\sbin\HPMPIWin32Service.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, SYSTEM\CurrentControlSet\Services\Eventlog\Application\HPMPI, EventMessageFile
Delete
C:\Windows\system32\psxss.exe
Script: Quarantine, Delete, BC delete
--Registry keyHKEY_LOCAL_MACHINE, System\CurrentControlSet\Control\Session Manager\SubSystems, Posix
progman.exe
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, shell
Delete
vgafix.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fixedfon.fon
Delete
vgaoem.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, oemfonts.fon
Delete
vgasys.fon
Script: Quarantine, Delete, BC delete
ActiveRegistry keyHKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\WOW\boot, fonts.fon
Delete
Autoruns items detected - 583, recognized as trusted - 577

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File nameTypeDescriptionManufacturerCLSID
Extension module{2670000A-7350-4f3c-8081-5663EE0C6C49}
Delete
Extension module{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
Delete
Elements detected - 11, recognized as trusted - 9

Windows Explorer extension modules

File nameDestinationDescriptionManufacturerCLSID
"C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Script: Quarantine, Delete, BC delete
Windows Live Photo Gallery Autoplay Drop Target{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
Delete
"C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Script: Quarantine, Delete, BC delete
Windows Live Photo Gallery Viewer Drop Target{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
Delete
"C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /PhotoViewerComServer {00F374B7-B390-4884-B372-2FC349F2172B}
Script: Quarantine, Delete, BC delete
Windows Live Photo Gallery Editor Drop Target{00F374B7-B390-4884-B372-2FC349F2172B}
Delete
Elements detected - 28, recognized as trusted - 25

Printing system extensions (print monitors, providers)

File nameTypeNameDescriptionManufacturer
Elements detected - 9, recognized as trusted - 9

Task Scheduler jobs

File nameJob nameJob statusDescriptionManufacturer
Elements detected - 0, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)
ProviderStatusEXE fileDescriptionGUID
Detected - 8, recognized as trusted - 8
Transport protocol providers (TSP, LSP)
ProviderEXE fileDescription
Detected - 32, recognized as trusted - 32
Results of automatic SPI settings check
LSP settings checked. No errors detected

TCP/UDP ports

PortStatusRemote HostRemote PortApplicationNotes
TCP ports
135LISTENING0.0.0.00[764] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
139LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
445LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2048LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
2869LISTENING0.0.0.00[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
10000LISTENING0.0.0.00[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532LISTENING0.0.0.00[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT2.49.68.1762086[0]   
18532TIME_WAIT2.49.113.12363365[0]   
18532TIME_WAIT2.49.138.357209[0]   
18532TIME_WAIT2.50.141.2363390[0]   
18532TIME_WAIT2.50.141.2363398[0]   
18532TIME_WAIT2.88.116.1031281[0]   
18532TIME_WAIT2.91.24.21223058[0]   
18532TIME_WAIT2.106.239.802464[0]   
18532TIME_WAIT14.201.194.11963133[0]   
18532ESTABLISHED24.0.35.15564597[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT24.6.159.6655121[0]   
18532SYN_RECEIVED24.6.159.6655469[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT24.57.248.20561651[0]   
18532TIME_WAIT24.80.101.10627629[0]   
18532TIME_WAIT24.80.101.10627643[0]   
18532TIME_WAIT24.108.12.2662222[0]   
18532TIME_WAIT24.109.54.22054210[0]   
18532TIME_WAIT24.138.35.21063711[0]   
18532ESTABLISHED24.141.152.14252440[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT24.142.22.7155039[0]   
18532TIME_WAIT24.143.226.1034478[0]   
18532ESTABLISHED24.184.118.9057419[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT24.188.104.25255119[0]   
18532TIME_WAIT24.188.104.25255247[0]   
18532TIME_WAIT24.200.71.6461222[0]   
18532TIME_WAIT24.213.76.1864365[0]   
18532SYN_RECEIVED24.213.76.1864425[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT24.226.62.2551380[0]   
18532TIME_WAIT27.32.176.1381448[0]   
18532TIME_WAIT41.68.12.5426824[0]   
18532TIME_WAIT41.68.12.5426922[0]   
18532FIN_WAIT241.132.15.17653878[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT41.218.237.1220479[0]   
18532TIME_WAIT41.242.122.13427150[0]   
18532TIME_WAIT46.40.21.11750125[0]   
18532TIME_WAIT46.184.200.23564715[0]   
18532TIME_WAIT46.184.200.23564757[0]   
18532TIME_WAIT50.36.165.8250054[0]   
18532TIME_WAIT50.36.165.8250287[0]   
18532TIME_WAIT50.36.185.2950627[0]   
18532TIME_WAIT50.88.230.7155475[0]   
18532TIME_WAIT50.98.224.24538812[0]   
18532TIME_WAIT58.96.52.22862884[0]   
18532TIME_WAIT58.182.120.13949585[0]   
18532TIME_WAIT58.182.208.2381314[0]   
18532TIME_WAIT58.182.208.2381359[0]   
18532TIME_WAIT59.189.60.19252700[0]   
18532TIME_WAIT60.240.204.23964595[0]   
18532FIN_WAIT60.240.204.23964823[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT60.241.234.23054995[0]   
18532ESTABLISHED65.52.69.6561478[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT65.94.57.1851062[0]   
18532TIME_WAIT65.94.57.1851121[0]   
18532TIME_WAIT65.94.57.1854981[0]   
18532TIME_WAIT65.94.99.4763603[0]   
18532TIME_WAIT65.94.99.4763686[0]   
18532TIME_WAIT65.198.187.116354[0]   
18532TIME_WAIT65.198.187.116869[0]   
18532ESTABLISHED66.44.119.12856127[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT66.66.115.22762781[0]   
18532TIME_WAIT66.66.115.22762839[0]   
18532ESTABLISHED66.183.100.7857743[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT67.149.217.2050616[0]   
18532TIME_WAIT67.149.217.2050787[0]   
18532TIME_WAIT67.171.176.20535969[0]   
18532TIME_WAIT67.171.176.20560973[0]   
18532TIME_WAIT67.180.107.10435642[0]   
18532TIME_WAIT67.180.107.10435848[0]   
18532TIME_WAIT67.181.107.3554862[0]   
18532TIME_WAIT67.190.12.1151225[0]   
18532TIME_WAIT67.202.108.7142299[0]   
18532ESTABLISHED67.219.75.14127154[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT68.39.65.14654588[0]   
18532TIME_WAIT68.45.245.15361699[0]   
18532TIME_WAIT68.52.239.19861478[0]   
18532TIME_WAIT68.62.251.1350601[0]   
18532TIME_WAIT68.62.251.1350649[0]   
18532TIME_WAIT68.144.213.4161259[0]   
18532TIME_WAIT68.149.15.6461149[0]   
18532TIME_WAIT68.151.228.2103549[0]   
18532TIME_WAIT69.80.16.7862941[0]   
18532TIME_WAIT69.80.16.7862998[0]   
18532ESTABLISHED69.138.115.1334657[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT69.158.133.734063[0]   
18532TIME_WAIT69.178.67.6163924[0]   
18532TIME_WAIT69.204.108.2450482[0]   
18532TIME_WAIT69.255.233.14961815[0]   
18532TIME_WAIT70.20.24.3159880[0]   
18532TIME_WAIT70.27.137.23451653[0]   
18532TIME_WAIT70.29.23.9261611[0]   
18532TIME_WAIT70.29.23.9261827[0]   
18532TIME_WAIT70.77.199.5859211[0]   
18532TIME_WAIT70.77.199.5859213[0]   
18532ESTABLISHED70.111.91.16950011[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT70.112.16.4560683[0]   
18532TIME_WAIT70.116.9.2054272[0]   
18532TIME_WAIT70.117.6.12256163[0]   
18532TIME_WAIT70.117.6.12256420[0]   
18532TIME_WAIT71.7.172.2759189[0]   
18532ESTABLISHED71.22.163.10651148[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT71.54.73.15018900[0]   
18532TIME_WAIT71.93.197.4452362[0]   
18532TIME_WAIT71.93.197.4452373[0]   
18532TIME_WAIT71.104.5.23350266[0]   
18532TIME_WAIT71.142.197.8752042[0]   
18532TIME_WAIT71.180.106.19453627[0]   
18532TIME_WAIT71.224.58.2261963[0]   
18532TIME_WAIT71.238.185.7065233[0]   
18532TIME_WAIT72.12.134.13860862[0]   
18532TIME_WAIT72.39.124.10557375[0]   
18532TIME_WAIT72.94.62.24958850[0]   
18532TIME_WAIT72.94.62.24958854[0]   
18532TIME_WAIT72.200.202.16054552[0]   
18532TIME_WAIT72.200.202.16054781[0]   
18532TIME_WAIT72.225.43.874766[0]   
18532TIME_WAIT72.227.140.16760691[0]   
18532TIME_WAIT72.252.106.7763826[0]   
18532TIME_WAIT72.252.106.7764143[0]   
18532TIME_WAIT74.15.133.23949457[0]   
18532TIME_WAIT74.46.66.20161312[0]   
18532TIME_WAIT74.66.238.14033525[0]   
18532TIME_WAIT74.66.238.14041363[0]   
18532TIME_WAIT74.78.19.12658211[0]   
18532TIME_WAIT74.102.198.20764529[0]   
18532TIME_WAIT74.102.198.20764707[0]   
18532TIME_WAIT74.247.60.4459063[0]   
18532TIME_WAIT75.74.106.7158671[0]   
18532TIME_WAIT75.82.219.5256414[0]   
18532TIME_WAIT75.111.128.17543229[0]   
18532TIME_WAIT75.143.146.82171[0]   
18532TIME_WAIT75.146.104.9054413[0]   
18532TIME_WAIT75.155.139.12855848[0]   
18532TIME_WAIT75.155.139.12855908[0]   
18532TIME_WAIT76.11.122.1031252[0]   
18532TIME_WAIT76.11.122.1031328[0]   
18532TIME_WAIT76.20.243.2357067[0]   
18532TIME_WAIT76.64.23.3961543[0]   
18532TIME_WAIT76.69.195.19251452[0]   
18532TIME_WAIT76.124.235.2454442[0]   
18532TIME_WAIT76.170.73.8655626[0]   
18532TIME_WAIT76.192.245.6062872[0]   
18532TIME_WAIT76.192.245.6063022[0]   
18532TIME_WAIT76.211.237.22053592[0]   
18532TIME_WAIT77.99.71.21365407[0]   
18532TIME_WAIT77.215.173.216756[0]   
18532TIME_WAIT77.215.242.228995[0]   
18532TIME_WAIT78.101.219.12152998[0]   
18532TIME_WAIT78.129.4.2057059[0]   
18532TIME_WAIT78.188.10.5861514[0]   
18532ESTABLISHED78.248.125.17858608[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT79.178.9.21956588[0]   
18532TIME_WAIT79.183.199.10355268[0]   
18532TIME_WAIT80.0.154.21360945[0]   
18532TIME_WAIT80.57.129.18556034[0]   
18532TIME_WAIT80.57.129.18556230[0]   
18532TIME_WAIT80.121.44.4957520[0]   
18532TIME_WAIT80.192.154.6554103[0]   
18532TIME_WAIT80.192.154.6554201[0]   
18532TIME_WAIT81.100.26.2525751[0]   
18532TIME_WAIT81.155.28.1259836[0]   
18532TIME_WAIT81.155.28.1260028[0]   
18532TIME_WAIT82.170.37.14314625[0]   
18532TIME_WAIT82.170.37.14314708[0]   
18532TIME_WAIT83.166.208.6063768[0]   
18532TIME_WAIT83.227.200.13149959[0]   
18532TIME_WAIT83.227.200.13152643[0]   
18532TIME_WAIT83.248.164.16362557[0]   
18532TIME_WAIT83.248.164.16362891[0]   
18532TIME_WAIT84.235.73.17157444[0]   
18532TIME_WAIT85.246.197.14050186[0]   
18532TIME_WAIT85.246.197.14050333[0]   
18532TIME_WAIT86.5.60.5553061[0]   
18532TIME_WAIT86.30.142.11454482[0]   
18532TIME_WAIT86.30.142.11454662[0]   
18532TIME_WAIT86.138.129.23451871[0]   
18532TIME_WAIT86.161.169.11024[0]   
18532TIME_WAIT87.91.112.6561569[0]   
18532TIME_WAIT87.112.119.20449398[0]   
18532TIME_WAIT87.194.34.10557852[0]   
18532TIME_WAIT87.194.34.10557946[0]   
18532TIME_WAIT87.200.42.24362209[0]   
18532TIME_WAIT87.210.160.7063839[0]   
18532TIME_WAIT87.210.160.7064141[0]   
18532TIME_WAIT88.193.171.20649741[0]   
18532TIME_WAIT88.196.233.20449236[0]   
18532TIME_WAIT88.196.233.20465348[0]   
18532TIME_WAIT89.34.46.13360564[0]   
18532ESTABLISHED89.142.31.4449804[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT89.172.202.23055426[0]   
18532TIME_WAIT89.212.43.17251663[0]   
18532TIME_WAIT89.237.130.1850660[0]   
18532ESTABLISHED90.199.34.17560226[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532ESTABLISHED90.200.103.8349445[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT90.200.161.5853874[0]   
18532TIME_WAIT90.219.238.24261204[0]   
18532TIME_WAIT92.16.6.12758436[0]   
18532TIME_WAIT92.96.222.24461200[0]   
18532TIME_WAIT92.96.222.24461542[0]   
18532TIME_WAIT92.97.154.3649417[0]   
18532TIME_WAIT92.97.154.3649646[0]   
18532TIME_WAIT92.97.244.7854756[0]   
18532TIME_WAIT92.97.244.7854916[0]   
18532TIME_WAIT92.98.92.4051240[0]   
18532TIME_WAIT92.98.92.4051324[0]   
18532TIME_WAIT92.241.90.2425932[0]   
18532ESTABLISHED92.241.90.2425991[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT93.97.29.23162644[0]   
18532TIME_WAIT94.14.254.22560651[0]   
18532TIME_WAIT94.99.3.8753823[0]   
18532TIME_WAIT94.170.143.12658396[0]   
18532TIME_WAIT94.170.143.12658519[0]   
18532TIME_WAIT94.195.191.5953210[0]   
18532TIME_WAIT94.195.191.5953587[0]   
18532TIME_WAIT94.202.191.17260130[0]   
18532TIME_WAIT94.208.24.9541418[0]   
18532TIME_WAIT94.208.24.9546832[0]   
18532ESTABLISHED96.48.8.10562642[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT96.48.77.17758425[0]   
18532TIME_WAIT96.48.77.17758717[0]   
18532ESTABLISHED96.49.37.7661988[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT96.49.187.18454779[0]   
18532TIME_WAIT96.51.216.2155442[0]   
18532TIME_WAIT96.52.228.24760330[0]   
18532TIME_WAIT96.54.14.15654951[0]   
18532TIME_WAIT96.54.14.15655121[0]   
18532TIME_WAIT96.54.102.18958691[0]   
18532ESTABLISHED96.61.169.10157746[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT96.245.61.15451716[0]   
18532TIME_WAIT97.102.30.3663125[0]   
18532TIME_WAIT98.18.46.20361566[0]   
18532TIME_WAIT98.28.232.10049689[0]   
18532TIME_WAIT98.111.164.2523447[0]   
18532TIME_WAIT98.116.76.5958752[0]   
18532TIME_WAIT98.116.76.5959108[0]   
18532TIME_WAIT98.116.175.13450805[0]   
18532TIME_WAIT98.164.254.6861728[0]   
18532ESTABLISHED98.165.132.22249273[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT98.165.248.5965274[0]   
18532TIME_WAIT98.196.16.1351192[0]   
18532TIME_WAIT98.227.95.11050981[0]   
18532TIME_WAIT98.243.71.15055391[0]   
18532TIME_WAIT98.252.207.18243391[0]   
18532TIME_WAIT99.163.95.19460240[0]   
18532TIME_WAIT99.163.95.19460466[0]   
18532TIME_WAIT99.199.50.18260105[0]   
18532TIME_WAIT99.227.252.13956493[0]   
18532TIME_WAIT99.227.252.13956630[0]   
18532TIME_WAIT99.227.252.13956770[0]   
18532TIME_WAIT99.239.181.3957589[0]   
18532TIME_WAIT99.242.90.762560[0]   
18532TIME_WAIT99.242.165.17965331[0]   
18532TIME_WAIT99.242.165.17965510[0]   
18532TIME_WAIT99.246.60.17661770[0]   
18532TIME_WAIT99.250.11.6050919[0]   
18532TIME_WAIT99.250.11.6050923[0]   
18532TIME_WAIT99.250.39.6661457[0]   
18532TIME_WAIT99.250.39.6661534[0]   
18532TIME_WAIT108.60.168.17961619[0]   
18532TIME_WAIT108.67.53.21456618[0]   
18532TIME_WAIT109.78.3.22441977[0]   
18532TIME_WAIT109.132.229.2189101[0]   
18532TIME_WAIT111.93.213.16750667[0]   
18532TIME_WAIT111.118.150.22427823[0]   
18532TIME_WAIT111.240.52.5424490[0]   
18532ESTABLISHED112.198.64.4326783[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT112.202.179.12755949[0]   
18532TIME_WAIT112.202.179.12756002[0]   
18532TIME_WAIT113.20.19.18662896[0]   
18532TIME_WAIT114.76.140.2131966[0]   
18532TIME_WAIT114.76.140.2132020[0]   
18532TIME_WAIT114.182.157.8555637[0]   
18532TIME_WAIT114.182.157.8555762[0]   
18532TIME_WAIT116.88.209.23461825[0]   
18532TIME_WAIT118.209.184.12961165[0]   
18532TIME_WAIT118.209.184.12961248[0]   
18532TIME_WAIT119.224.218.12660579[0]   
18532TIME_WAIT119.225.8.244602[0]   
18532ESTABLISHED119.235.54.1044083[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT120.28.190.13855325[0]   
18532TIME_WAIT120.61.2.24112066[0]   
18532TIME_WAIT121.7.60.4953867[0]   
18532TIME_WAIT121.7.60.4953964[0]   
18532TIME_WAIT121.45.159.14949702[0]   
18532ESTABLISHED121.45.222.1851432[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT121.213.160.5765212[0]   
18532TIME_WAIT121.213.160.5765265[0]   
18532TIME_WAIT121.219.154.2764631[0]   
18532TIME_WAIT121.219.154.2764692[0]   
18532TIME_WAIT121.219.154.2764728[0]   
18532SYN_RECEIVED122.109.108.15056419[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT122.174.89.23558956[0]   
18532TIME_WAIT122.174.89.23559003[0]   
18532TIME_WAIT123.236.184.356395[0]   
18532TIME_WAIT124.43.233.15764927[0]   
18532TIME_WAIT124.148.220.10439811[0]   
18532TIME_WAIT124.168.244.18859533[0]   
18532TIME_WAIT124.168.244.18859600[0]   
18532TIME_WAIT124.169.209.1622911[0]   
18532TIME_WAIT124.169.232.1062363[0]   
18532TIME_WAIT124.176.252.149806[0]   
18532TIME_WAIT124.176.252.150061[0]   
18532SYN_RECEIVED124.190.234.5162603[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT131.227.236.12354987[0]   
18532TIME_WAIT137.229.110.2461347[0]   
18532TIME_WAIT137.229.110.2461771[0]   
18532TIME_WAIT142.163.134.14960085[0]   
18532TIME_WAIT145.107.8.10251032[0]   
18532TIME_WAIT145.107.8.10251214[0]   
18532TIME_WAIT151.95.27.2058964[0]   
18532TIME_WAIT151.95.27.2059216[0]   
18532TIME_WAIT168.167.195.20854744[0]   
18532TIME_WAIT168.167.195.20854877[0]   
18532TIME_WAIT173.33.90.631326[0]   
18532TIME_WAIT173.34.56.10860951[0]   
18532FIN_WAIT173.35.92.19656705[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT173.35.115.2560857[0]   
18532TIME_WAIT173.35.168.2094309[0]   
18532TIME_WAIT173.52.78.12263230[0]   
18532TIME_WAIT173.52.78.12263334[0]   
18532TIME_WAIT173.56.112.21757115[0]   
18532ESTABLISHED173.75.190.22664955[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT173.163.192.5860794[0]   
18532TIME_WAIT173.163.192.5860901[0]   
18532TIME_WAIT173.179.168.9462681[0]   
18532TIME_WAIT173.179.168.9462894[0]   
18532TIME_WAIT173.183.37.19260685[0]   
18532TIME_WAIT173.183.37.19261604[0]   
18532TIME_WAIT173.206.249.18663126[0]   
18532TIME_WAIT173.206.249.18663198[0]   
18532TIME_WAIT173.212.96.1202562[0]   
18532TIME_WAIT173.212.96.1202627[0]   
18532TIME_WAIT173.217.70.9955989[0]   
18532TIME_WAIT174.1.105.5957493[0]   
18532TIME_WAIT174.3.215.1843109[0]   
18532TIME_WAIT174.3.215.1843216[0]   
18532TIME_WAIT174.5.77.21164065[0]   
18532TIME_WAIT174.5.105.3358806[0]   
18532TIME_WAIT174.5.105.3359062[0]   
18532TIME_WAIT174.89.26.2054240[0]   
18532TIME_WAIT174.102.66.23159051[0]   
18532TIME_WAIT174.102.66.23159221[0]   
18532TIME_WAIT174.106.20.6764359[0]   
18532TIME_WAIT174.106.20.6764548[0]   
18532TIME_WAIT174.108.4.6858475[0]   
18532TIME_WAIT174.108.4.6858486[0]   
18532TIME_WAIT174.112.2.4864094[0]   
18532TIME_WAIT174.112.2.4864095[0]   
18532TIME_WAIT174.113.18.11350569[0]   
18532TIME_WAIT174.115.45.9463197[0]   
18532TIME_WAIT174.117.251.14156265[0]   
18532TIME_WAIT174.117.251.14156389[0]   
18532TIME_WAIT174.155.88.1963080[0]   
18532TIME_WAIT175.136.60.960898[0]   
18532TIME_WAIT175.136.174.18839437[0]   
18532TIME_WAIT175.145.215.673910[0]   
18532TIME_WAIT176.44.95.8340754[0]   
18532TIME_WAIT177.40.149.1552157[0]   
18532TIME_WAIT177.40.149.1552844[0]   
18532TIME_WAIT178.77.152.1952657[0]   
18532TIME_WAIT178.131.159.19856616[0]   
18532ESTABLISHED178.253.210.20111154[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT180.148.38.1753927[0]   
18532TIME_WAIT180.188.237.22755779[0]   
18532TIME_WAIT180.188.237.22755795[0]   
18532TIME_WAIT180.191.34.8660738[0]   
18532TIME_WAIT180.215.1.24150896[0]   
18532TIME_WAIT180.215.185.24652363[0]   
18532TIME_WAIT184.65.11.314427[0]   
18532TIME_WAIT184.65.11.314515[0]   
18532TIME_WAIT187.53.29.1152329[0]   
18532TIME_WAIT187.53.29.1152425[0]   
18532TIME_WAIT189.13.198.20059757[0]   
18532TIME_WAIT192.194.227.1824023[0]   
18532TIME_WAIT194.144.99.452707[0]   
18532TIME_WAIT195.42.128.6661848[0]   
18532TIME_WAIT195.42.128.6662143[0]   
18532TIME_WAIT195.150.86.7564967[0]   
18532TIME_WAIT196.209.225.18658347[0]   
18532TIME_WAIT201.78.253.3712173[0]   
18532ESTABLISHED201.79.104.652449[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT203.129.46.5756343[0]   
18532TIME_WAIT203.218.68.13849630[0]   
18532TIME_WAIT203.218.68.13849758[0]   
18532TIME_WAIT204.83.50.556197[0]   
18532TIME_WAIT206.45.54.24358898[0]   
18532TIME_WAIT206.223.181.93587[0]   
18532TIME_WAIT206.223.181.93588[0]   
18532TIME_WAIT206.223.181.93650[0]   
18532TIME_WAIT206.223.181.93652[0]   
18532TIME_WAIT207.6.147.21861734[0]   
18532TIME_WAIT207.47.211.23660603[0]   
18532TIME_WAIT207.255.176.19432800[0]   
18532TIME_WAIT207.255.176.19445873[0]   
18532TIME_WAIT208.96.95.9356060[0]   
18532TIME_WAIT208.96.95.9356102[0]   
18532TIME_WAIT208.101.112.15251854[0]   
18532TIME_WAIT208.127.69.10563031[0]   
18532TIME_WAIT209.6.66.15659470[0]   
18532TIME_WAIT209.6.66.15659574[0]   
18532TIME_WAIT209.59.76.18063920[0]   
18532TIME_WAIT209.115.246.23040153[0]   
18532TIME_WAIT209.115.246.23047969[0]   
18532TIME_WAIT209.121.151.23053707[0]   
18532TIME_WAIT209.195.80.5151009[0]   
18532TIME_WAIT210.49.68.9859331[0]   
18532TIME_WAIT212.116.206.10024591[0]   
18532TIME_WAIT212.116.206.10024813[0]   
18532TIME_WAIT213.55.108.11346736[0]   
18532ESTABLISHED213.101.236.16262717[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532TIME_WAIT216.8.181.18658186[0]   
18532TIME_WAIT220.157.134.459164[0]   
18532TIME_WAIT220.233.18.3317569[0]   
18532TIME_WAIT220.233.18.3317589[0]   
49152LISTENING0.0.0.00[444] c:\windows\system32\wininit.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49153LISTENING0.0.0.00[824] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49154LISTENING0.0.0.00[928] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49155LISTENING0.0.0.00[1344] c:\windows\system32\spoolsv.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49156LISTENING0.0.0.00[500] c:\windows\system32\services.exe
Script: Quarantine, Delete, BC delete, Terminate
 
49157LISTENING0.0.0.00[516] c:\windows\system32\lsass.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53140ESTABLISHED64.4.61.1281863[3576] c:\program files\windows live\contacts\wlcomm.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53163ESTABLISHED65.54.77.72443[1768] c:\program files\windows live\mesh\wlcrasvc.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53164ESTABLISHED65.55.202.197443[2856] c:\program files\windows live\mesh\moe.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53169ESTABLISHED65.55.17.3980[2640] c:\program files\htc home 1.10\htchome.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53967ESTABLISHED38.117.98.20480[5092] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
53968ESTABLISHED38.117.98.20480[5092] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
56030ESTABLISHED76.125.37.24957021[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
UDP ports
9LISTENING----[2856] c:\program files\windows live\mesh\moe.exe
Script: Quarantine, Delete, BC delete, Terminate
 
137LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
138LISTENING----[4] System
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3664] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
1900LISTENING----[3664] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
5355LISTENING----[1204] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
6771LISTENING----[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
18532LISTENING----[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
50651LISTENING----[3684] c:\program files\utorrent\utorrent.exe
Script: Quarantine, Delete, BC delete, Terminate
 
52132LISTENING----[5684] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
52623LISTENING----[5280] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54608LISTENING----[5092] c:\program files\internet explorer\iexplore.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54683LISTENING----[3664] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
54684LISTENING----[3664] c:\windows\system32\svchost.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59426LISTENING----[3576] c:\program files\windows live\contacts\wlcomm.exe
Script: Quarantine, Delete, BC delete, Terminate
 
59898LISTENING----[2856] c:\program files\windows live\mesh\moe.exe
Script: Quarantine, Delete, BC delete, Terminate
 

Downloaded Program Files (DPF)

File nameDescriptionManufacturerCLSIDSource URL
{E6F480FC-BD44-4CBA-B74A-89AF7842937D}
Delete
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.21.0.cab
Elements detected - 6, recognized as trusted - 5

Control Panel Applets (CPL)

File nameDescriptionManufacturer
Elements detected - 21, recognized as trusted - 21

Active Setup

File nameDescriptionManufacturerCLSID
Elements detected - 9, recognized as trusted - 9

HOSTS file

Hosts file record
127.0.0.1       localhost

Protocols and handlers

File nameTypeDescriptionManufacturerCLSID
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
mscoree.dll
Script: Quarantine, Delete, BC delete
ProtocolMicrosoft .NET Runtime Execution Engine ()© Microsoft Corporation. All rights reserved.{1E66F26B-79EE-11D2-8710-00C04F79ED0D}
Elements detected - 17, recognized as trusted - 14

Suspicious objects

FileDescriptionType
C:\Windows\system32\certvert.dll
Script: Quarantine, Delete, BC delete
Suspicion by Heuristic analysis HSC: suspicion for hidden autorun AppCertDlls (high degree of probability)


Main script of analysis
Windows version: Windows 7 Professional, Build=7600, SP=""
System Restore: enabled
1.1 Searching for user-mode API hooks
 Analysis: kernel32.dll, export table found in section .text
IAT modification detected: CreateProcessA - 003B0010<>774E2062
IAT modification detected: GetModuleFileNameA - 003B0080<>77531094
IAT modification detected: GetModuleFileNameW - 003B00F0<>77532A14
IAT modification detected: CreateProcessW - 003B0160<>774E202D
IAT modification detected: LoadLibraryW - 003B0240<>775328D2
IAT modification detected: LoadLibraryA - 003B0320<>77532884
IAT modification detected: GetProcAddress - 003B0390<>77531857
IAT modification detected: FreeLibrary - 003B0400<>77531A09
 Analysis: ntdll.dll, export table found in section .text
 Analysis: user32.dll, export table found in section .text
 Analysis: advapi32.dll, export table found in section .text
Function advapi32.dll:AddMandatoryAce (1029) intercepted, method ProcAddressHijack.GetProcAddress ->764024B5->75F8193A
Function advapi32.dll:I_QueryTagInformation (1361) intercepted, method ProcAddressHijack.GetProcAddress ->76402655->77D172D8
Function advapi32.dll:I_ScIsSecurityProcess (1362) intercepted, method ProcAddressHijack.GetProcAddress ->7640268C->77D1733F
Function advapi32.dll:I_ScPnPGetServiceName (1363) intercepted, method ProcAddressHijack.GetProcAddress ->764026C3->77D17C40
Function advapi32.dll:I_ScQueryServiceConfig (1364) intercepted, method ProcAddressHijack.GetProcAddress ->764026FA->77D15F8A
Function advapi32.dll:I_ScSendPnPMessage (1365) intercepted, method ProcAddressHijack.GetProcAddress ->76402732->77D15E7D
Function advapi32.dll:I_ScSendTSMessage (1366) intercepted, method ProcAddressHijack.GetProcAddress ->76402766->77D171C5
Function advapi32.dll:I_ScValidatePnPService (1369) intercepted, method ProcAddressHijack.GetProcAddress ->76402799->77D16B9D
Function advapi32.dll:IsValidRelativeSecurityDescriptor (1389) intercepted, method ProcAddressHijack.GetProcAddress ->764027D1->75F7977E
Function advapi32.dll:PerfCreateInstance (1515) intercepted, method ProcAddressHijack.GetProcAddress ->76402858->752A2187
Function advapi32.dll:PerfDecrementULongCounterValue (1516) intercepted, method ProcAddressHijack.GetProcAddress ->76402871->752A2A1D
Function advapi32.dll:PerfDecrementULongLongCounterValue (1517) intercepted, method ProcAddressHijack.GetProcAddress ->76402896->752A2B3C
Function advapi32.dll:PerfDeleteInstance (1519) intercepted, method ProcAddressHijack.GetProcAddress ->764028BF->752A2259
Function advapi32.dll:PerfIncrementULongCounterValue (1522) intercepted, method ProcAddressHijack.GetProcAddress ->764028D8->752A27B9
Function advapi32.dll:PerfIncrementULongLongCounterValue (1523) intercepted, method ProcAddressHijack.GetProcAddress ->764028FD->752A28D6
Function advapi32.dll:PerfQueryInstance (1528) intercepted, method ProcAddressHijack.GetProcAddress ->76402926->752A2373
Function advapi32.dll:PerfSetCounterRefValue (1529) intercepted, method ProcAddressHijack.GetProcAddress ->7640293E->752A2447
Function advapi32.dll:PerfSetCounterSetInfo (1530) intercepted, method ProcAddressHijack.GetProcAddress ->7640295B->752A20B0
Function advapi32.dll:PerfSetULongCounterValue (1531) intercepted, method ProcAddressHijack.GetProcAddress ->76402977->752A2565
Function advapi32.dll:PerfSetULongLongCounterValue (1532) intercepted, method ProcAddressHijack.GetProcAddress ->76402996->752A2680
Function advapi32.dll:PerfStartProvider (1533) intercepted, method ProcAddressHijack.GetProcAddress ->764029B9->752A1FED
Function advapi32.dll:PerfStartProviderEx (1534) intercepted, method ProcAddressHijack.GetProcAddress ->764029D1->752A1F34
Function advapi32.dll:PerfStopProvider (1535) intercepted, method ProcAddressHijack.GetProcAddress ->764029EB->752A2026
Function advapi32.dll:SystemFunction035 (1753) intercepted, method ProcAddressHijack.GetProcAddress ->76402A3C->75783EA8
 Analysis: ws2_32.dll, export table found in section .text
 Analysis: wininet.dll, export table found in section .text
 Analysis: rasapi32.dll, export table found in section .text
 Analysis: urlmon.dll, export table found in section .text
 Analysis: netapi32.dll, export table found in section .text
Function netapi32.dll:DavAddConnection (1) intercepted, method ProcAddressHijack.GetProcAddress ->74163B10->693029DD
Function netapi32.dll:DavDeleteConnection (2) intercepted, method ProcAddressHijack.GetProcAddress ->74163B29->6930181B
Function netapi32.dll:DavFlushFile (3) intercepted, method ProcAddressHijack.GetProcAddress ->74163B45->69301713
Function netapi32.dll:DavGetExtendedError (4) intercepted, method ProcAddressHijack.GetProcAddress ->74163B5A->69302347
Function netapi32.dll:DavGetHTTPFromUNCPath (5) intercepted, method ProcAddressHijack.GetProcAddress ->74163B76->6930275B
Function netapi32.dll:DavGetUNCFromHTTPPath (6) intercepted, method ProcAddressHijack.GetProcAddress ->74163B94->6930257D
Function netapi32.dll:DsAddressToSiteNamesA (7) intercepted, method ProcAddressHijack.GetProcAddress ->74163BB2->755E4A4D
Function netapi32.dll:DsAddressToSiteNamesExA (8) intercepted, method ProcAddressHijack.GetProcAddress ->74163BD1->755E4D79
Function netapi32.dll:DsAddressToSiteNamesExW (9) intercepted, method ProcAddressHijack.GetProcAddress ->74163BF2->755E5049
Function netapi32.dll:DsAddressToSiteNamesW (10) intercepted, method ProcAddressHijack.GetProcAddress ->74163C13->755E4C29
Function netapi32.dll:DsDeregisterDnsHostRecordsA (11) intercepted, method ProcAddressHijack.GetProcAddress ->74163C32->755E6DD9
Function netapi32.dll:DsDeregisterDnsHostRecordsW (12) intercepted, method ProcAddressHijack.GetProcAddress ->74163C57->755E6D59
Function netapi32.dll:DsEnumerateDomainTrustsA (13) intercepted, method ProcAddressHijack.GetProcAddress ->74163C7C->755E6771
Function netapi32.dll:DsEnumerateDomainTrustsW (14) intercepted, method ProcAddressHijack.GetProcAddress ->74163C9E->755D60BC
Function netapi32.dll:DsGetDcCloseW (15) intercepted, method ProcAddressHijack.GetProcAddress ->74163CC0->755E495D
Function netapi32.dll:DsGetDcNameA (16) intercepted, method ProcAddressHijack.GetProcAddress ->74163CD7->755E5BB2
Function netapi32.dll:DsGetDcNameW (17) intercepted, method ProcAddressHijack.GetProcAddress ->74163CED->755D4CA8
Function netapi32.dll:DsGetDcNameWithAccountA (18) intercepted, method ProcAddressHijack.GetProcAddress ->74163D03->755E55E9
Function netapi32.dll:DsGetDcNameWithAccountW (19) intercepted, method ProcAddressHijack.GetProcAddress ->74163D24->755D4CD1
Function netapi32.dll:DsGetDcNextA (20) intercepted, method ProcAddressHijack.GetProcAddress ->74163D45->755E4896
Function netapi32.dll:DsGetDcNextW (21) intercepted, method ProcAddressHijack.GetProcAddress ->74163D5B->755E47ED
Function netapi32.dll:DsGetDcOpenA (22) intercepted, method ProcAddressHijack.GetProcAddress ->74163D71->755E473D
Function netapi32.dll:DsGetDcOpenW (23) intercepted, method ProcAddressHijack.GetProcAddress ->74163D87->755E46AB
Function netapi32.dll:DsGetDcSiteCoverageA (24) intercepted, method ProcAddressHijack.GetProcAddress ->74163D9D->755E5239
Function netapi32.dll:DsGetDcSiteCoverageW (25) intercepted, method ProcAddressHijack.GetProcAddress ->74163DBB->755E5409
Function netapi32.dll:DsGetForestTrustInformationW (26) intercepted, method ProcAddressHijack.GetProcAddress ->74163DD9->755E6E6F
Function netapi32.dll:DsGetSiteNameA (27) intercepted, method ProcAddressHijack.GetProcAddress ->74163DFF->755E5B39
Function netapi32.dll:DsGetSiteNameW (28) intercepted, method ProcAddressHijack.GetProcAddress ->74163E17->755D5F24
Function netapi32.dll:DsMergeForestTrustInformationW (29) intercepted, method ProcAddressHijack.GetProcAddress ->74163E2F->755E6F71
Function netapi32.dll:DsRoleAbortDownlevelServerUpgrade (30) intercepted, method ProcAddressHijack.GetProcAddress ->74163E57->74194339
Function netapi32.dll:DsRoleCancel (31) intercepted, method ProcAddressHijack.GetProcAddress ->74163E80->741934A9
Function netapi32.dll:DsRoleDcAsDc (32) intercepted, method ProcAddressHijack.GetProcAddress ->74163E94->74193EAD
Function netapi32.dll:DsRoleDcAsReplica (33) intercepted, method ProcAddressHijack.GetProcAddress ->74163EA8->74193F99
Function netapi32.dll:DsRoleDemoteDc (34) intercepted, method ProcAddressHijack.GetProcAddress ->74163EC1->74194189
Function netapi32.dll:DsRoleDnsNameToFlatName (35) intercepted, method ProcAddressHijack.GetProcAddress ->74163ED7->741932B5
Function netapi32.dll:DsRoleFreeMemory (36) intercepted, method ProcAddressHijack.GetProcAddress ->74163EF6->741919A9
Function netapi32.dll:DsRoleGetDatabaseFacts (37) intercepted, method ProcAddressHijack.GetProcAddress ->74163F0E->74193651
Function netapi32.dll:DsRoleGetDcOperationProgress (38) intercepted, method ProcAddressHijack.GetProcAddress ->74163F2C->74193351
Function netapi32.dll:DsRoleGetDcOperationResults (39) intercepted, method ProcAddressHijack.GetProcAddress ->74163F50->74193401
Function netapi32.dll:DsRoleGetPrimaryDomainInformation (40) intercepted, method ProcAddressHijack.GetProcAddress ->74163F73->74191F3D
Function netapi32.dll:DsRoleIfmHandleFree (41) intercepted, method ProcAddressHijack.GetProcAddress ->74163F9C->74193539
Function netapi32.dll:DsRoleServerSaveStateForUpgrade (42) intercepted, method ProcAddressHijack.GetProcAddress ->74163FB7->741935C9
Function netapi32.dll:DsRoleUpgradeDownlevelServer (43) intercepted, method ProcAddressHijack.GetProcAddress ->74163FDE->74194261
Function netapi32.dll:DsValidateSubnetNameA (44) intercepted, method ProcAddressHijack.GetProcAddress ->74164002->755E5AF9
Function netapi32.dll:DsValidateSubnetNameW (45) intercepted, method ProcAddressHijack.GetProcAddress ->74164021->755E49E1
Function netapi32.dll:I_BrowserDebugCall (46) intercepted, method ProcAddressHijack.GetProcAddress ->74164040->5BC124A9
Function netapi32.dll:I_BrowserDebugTrace (47) intercepted, method ProcAddressHijack.GetProcAddress ->7416405B->5BC12581
Function netapi32.dll:I_BrowserQueryEmulatedDomains (48) intercepted, method ProcAddressHijack.GetProcAddress ->74164077->5BC129F9
Function netapi32.dll:I_BrowserQueryOtherDomains (49) intercepted, method ProcAddressHijack.GetProcAddress ->7416409D->5BC122C1
Function netapi32.dll:I_BrowserQueryStatistics (50) intercepted, method ProcAddressHijack.GetProcAddress ->741640C0->5BC12651
Function netapi32.dll:I_BrowserResetNetlogonState (51) intercepted, method ProcAddressHijack.GetProcAddress ->741640E1->5BC123D1
Function netapi32.dll:I_BrowserResetStatistics (52) intercepted, method ProcAddressHijack.GetProcAddress ->74164105->5BC12729
Function netapi32.dll:I_BrowserServerEnum (53) intercepted, method ProcAddressHijack.GetProcAddress ->74164126->5BC120BF
Function netapi32.dll:I_BrowserSetNetlogonState (54) intercepted, method ProcAddressHijack.GetProcAddress ->74164142->5BC12919
Function netapi32.dll:I_DsUpdateReadOnlyServerDnsRecords (55) intercepted, method ProcAddressHijack.GetProcAddress ->74164164->755E5569
Function netapi32.dll:I_NetAccountDeltas (56) intercepted, method ProcAddressHijack.GetProcAddress ->74164190->755E63AB
Function netapi32.dll:I_NetAccountSync (57) intercepted, method ProcAddressHijack.GetProcAddress ->741641AC->755E63AB
Function netapi32.dll:I_NetChainSetClientAttributes (59) intercepted, method ProcAddressHijack.GetProcAddress ->741641C6->755E6FA6
Function netapi32.dll:I_NetChainSetClientAttributes2 (58) intercepted, method ProcAddressHijack.GetProcAddress ->741641ED->755E7029
Function netapi32.dll:I_NetDatabaseDeltas (60) intercepted, method ProcAddressHijack.GetProcAddress ->74164215->755E6391
Function netapi32.dll:I_NetDatabaseRedo (61) intercepted, method ProcAddressHijack.GetProcAddress ->74164232->755E6521
Function netapi32.dll:I_NetDatabaseSync (63) intercepted, method ProcAddressHijack.GetProcAddress ->7416424D->755E6391
Function netapi32.dll:I_NetDatabaseSync2 (62) intercepted, method ProcAddressHijack.GetProcAddress ->74164268->755E639E
Function netapi32.dll:I_NetDfsGetVersion (64) intercepted, method ProcAddressHijack.GetProcAddress ->74164284->75B57CA1
Function netapi32.dll:I_NetDfsIsThisADomainName (65) intercepted, method ProcAddressHijack.GetProcAddress ->7416429E->622E4E39
Function netapi32.dll:I_NetGetDCList (66) intercepted, method ProcAddressHijack.GetProcAddress ->741642BF->755E5D9C
Function netapi32.dll:I_NetGetForestTrustInformation (67) intercepted, method ProcAddressHijack.GetProcAddress ->741642D7->755E6EF1
Function netapi32.dll:I_NetLogonControl (69) intercepted, method ProcAddressHijack.GetProcAddress ->741642FF->755E63B8
Function netapi32.dll:I_NetLogonControl2 (68) intercepted, method ProcAddressHijack.GetProcAddress ->7416431A->755E6439
Function netapi32.dll:I_NetLogonGetDomainInfo (70) intercepted, method ProcAddressHijack.GetProcAddress ->74164336->755D64A4
Function netapi32.dll:I_NetLogonSamLogoff (71) intercepted, method ProcAddressHijack.GetProcAddress ->74164357->755E6091
Function netapi32.dll:I_NetLogonSamLogon (72) intercepted, method ProcAddressHijack.GetProcAddress ->74164374->755E5F39
Function netapi32.dll:I_NetLogonSamLogonEx (73) intercepted, method ProcAddressHijack.GetProcAddress ->74164390->755E5FE1
Function netapi32.dll:I_NetLogonSamLogonWithFlags (74) intercepted, method ProcAddressHijack.GetProcAddress ->741643AE->755DB22A
Function netapi32.dll:I_NetLogonSendToSam (75) intercepted, method ProcAddressHijack.GetProcAddress ->741643D3->755E6111
Function netapi32.dll:I_NetLogonUasLogoff (76) intercepted, method ProcAddressHijack.GetProcAddress ->741643F0->755E5EC9
Function netapi32.dll:I_NetLogonUasLogon (77) intercepted, method ProcAddressHijack.GetProcAddress ->7416440D->755E5E53
Function netapi32.dll:I_NetServerAuthenticate (80) intercepted, method ProcAddressHijack.GetProcAddress ->74164429->755E6191
Function netapi32.dll:I_NetServerAuthenticate2 (78) intercepted, method ProcAddressHijack.GetProcAddress ->7416444A->755E6211
Function netapi32.dll:I_NetServerAuthenticate3 (79) intercepted, method ProcAddressHijack.GetProcAddress ->7416446C->755D6393
Function netapi32.dll:I_NetServerGetTrustInfo (81) intercepted, method ProcAddressHijack.GetProcAddress ->7416448E->755E6C61
Function netapi32.dll:I_NetServerPasswordGet (82) intercepted, method ProcAddressHijack.GetProcAddress ->741644AF->755E6B61
Function netapi32.dll:I_NetServerPasswordSet (84) intercepted, method ProcAddressHijack.GetProcAddress ->741644CF->755E6291
Function netapi32.dll:I_NetServerPasswordSet2 (83) intercepted, method ProcAddressHijack.GetProcAddress ->741644EF->755E6311
Function netapi32.dll:I_NetServerReqChallenge (85) intercepted, method ProcAddressHijack.GetProcAddress ->74164510->755D6424
Function netapi32.dll:I_NetServerSetServiceBits (86) intercepted, method ProcAddressHijack.GetProcAddress ->74164531->75B5426D
Function netapi32.dll:I_NetServerSetServiceBitsEx (87) intercepted, method ProcAddressHijack.GetProcAddress ->74164552->75B56D11
Function netapi32.dll:I_NetServerTrustPasswordsGet (88) intercepted, method ProcAddressHijack.GetProcAddress ->74164575->755E6BE1
Function netapi32.dll:I_NetlogonComputeClientDigest (89) intercepted, method ProcAddressHijack.GetProcAddress ->7416459B->755D5C20
Function netapi32.dll:I_NetlogonComputeServerDigest (90) intercepted, method ProcAddressHijack.GetProcAddress ->741645C2->755E6AEC
Function netapi32.dll:NetAddAlternateComputerName (97) intercepted, method ProcAddressHijack.GetProcAddress ->741645E9->74135B21
Function netapi32.dll:NetAddServiceAccount (98) intercepted, method ProcAddressHijack.GetProcAddress ->7416460C->755E70B1
Function netapi32.dll:NetApiBufferAllocate (101) intercepted, method ProcAddressHijack.GetProcAddress ->7416462A->74151415
Function netapi32.dll:NetApiBufferFree (102) intercepted, method ProcAddressHijack.GetProcAddress ->74164648->741513D2
Function netapi32.dll:NetApiBufferReallocate (103) intercepted, method ProcAddressHijack.GetProcAddress ->74164662->74153729
Function netapi32.dll:NetApiBufferSize (104) intercepted, method ProcAddressHijack.GetProcAddress ->74164682->74153771
Function netapi32.dll:NetBrowserStatisticsGet (108) intercepted, method ProcAddressHijack.GetProcAddress ->7416469C->5BC12801
Function netapi32.dll:NetConnectionEnum (112) intercepted, method ProcAddressHijack.GetProcAddress ->741646BC->75B55521
Function netapi32.dll:NetDfsAdd (113) intercepted, method ProcAddressHijack.GetProcAddress ->741646D5->622E78FD
Function netapi32.dll:NetDfsAddFtRoot (114) intercepted, method ProcAddressHijack.GetProcAddress ->741646E6->622E6859
Function netapi32.dll:NetDfsAddRootTarget (115) intercepted, method ProcAddressHijack.GetProcAddress ->741646FD->622E7401
Function netapi32.dll:NetDfsAddStdRoot (116) intercepted, method ProcAddressHijack.GetProcAddress ->74164718->622E2B1E
Function netapi32.dll:NetDfsAddStdRootForced (117) intercepted, method ProcAddressHijack.GetProcAddress ->74164730->622E2BB1
Function netapi32.dll:NetDfsEnum (118) intercepted, method ProcAddressHijack.GetProcAddress ->7416474E->622E70F9
Function netapi32.dll:NetDfsGetClientInfo (119) intercepted, method ProcAddressHijack.GetProcAddress ->74164760->622E3F25
Function netapi32.dll:NetDfsGetDcAddress (120) intercepted, method ProcAddressHijack.GetProcAddress ->7416477B->622E2C51
Function netapi32.dll:NetDfsGetFtContainerSecurity (121) intercepted, method ProcAddressHijack.GetProcAddress ->74164795->622E5363
Function netapi32.dll:NetDfsGetInfo (122) intercepted, method ProcAddressHijack.GetProcAddress ->741647B9->622E2D69
Function netapi32.dll:NetDfsGetSecurity (123) intercepted, method ProcAddressHijack.GetProcAddress ->741647CE->622E7741
Function netapi32.dll:NetDfsGetStdContainerSecurity (124) intercepted, method ProcAddressHijack.GetProcAddress ->741647E7->622E3AD5
Function netapi32.dll:NetDfsGetSupportedNamespaceVersion (125) intercepted, method ProcAddressHijack.GetProcAddress ->7416480C->622E5C19
Function netapi32.dll:NetDfsManagerGetConfigInfo (126) intercepted, method ProcAddressHijack.GetProcAddress ->74164836->622E2E9C
Function netapi32.dll:NetDfsManagerInitialize (127) intercepted, method ProcAddressHijack.GetProcAddress ->74164858->622E2F91
Function netapi32.dll:NetDfsManagerSendSiteInfo (128) intercepted, method ProcAddressHijack.GetProcAddress ->74164877->622E72C5
Function netapi32.dll:NetDfsMove (129) intercepted, method ProcAddressHijack.GetProcAddress ->74164898->622E5651
Function netapi32.dll:NetDfsRemove (130) intercepted, method ProcAddressHijack.GetProcAddress ->741648AA->622E7A19
Function netapi32.dll:NetDfsRemoveFtRoot (131) intercepted, method ProcAddressHijack.GetProcAddress ->741648BE->622E6A99
Function netapi32.dll:NetDfsRemoveFtRootForced (132) intercepted, method ProcAddressHijack.GetProcAddress ->741648D8->622E6BE5
Function netapi32.dll:NetDfsRemoveRootTarget (133) intercepted, method ProcAddressHijack.GetProcAddress ->741648F8->622E5879
Function netapi32.dll:NetDfsRemoveStdRoot (134) intercepted, method ProcAddressHijack.GetProcAddress ->74164916->622E2CE1
Function netapi32.dll:NetDfsRename (135) intercepted, method ProcAddressHijack.GetProcAddress ->74164931->622E2E91
Function netapi32.dll:NetDfsSetClientInfo (136) intercepted, method ProcAddressHijack.GetProcAddress ->74164945->622E4301
Function netapi32.dll:NetDfsSetFtContainerSecurity (137) intercepted, method ProcAddressHijack.GetProcAddress ->74164960->622E53AF
Function netapi32.dll:NetDfsSetInfo (138) intercepted, method ProcAddressHijack.GetProcAddress ->74164984->622E6D8B
Function netapi32.dll:NetDfsSetSecurity (139) intercepted, method ProcAddressHijack.GetProcAddress ->74164999->622E7822
Function netapi32.dll:NetDfsSetStdContainerSecurity (140) intercepted, method ProcAddressHijack.GetProcAddress ->741649B2->622E3B24
Function netapi32.dll:NetEnumerateComputerNames (141) intercepted, method ProcAddressHijack.GetProcAddress ->741649D7->74135E39
Function netapi32.dll:NetEnumerateServiceAccounts (142) intercepted, method ProcAddressHijack.GetProcAddress ->741649F8->755E7199
Function netapi32.dll:NetEnumerateTrustedDomains (143) intercepted, method ProcAddressHijack.GetProcAddress ->74164A1D->755E652E
Function netapi32.dll:NetFileClose (147) intercepted, method ProcAddressHijack.GetProcAddress ->74164A41->75B55659
Function netapi32.dll:NetFileEnum (148) intercepted, method ProcAddressHijack.GetProcAddress ->74164A55->75B55729
Function netapi32.dll:NetFileGetInfo (149) intercepted, method ProcAddressHijack.GetProcAddress ->74164A68->75B55859
Function netapi32.dll:NetGetAnyDCName (150) intercepted, method ProcAddressHijack.GetProcAddress ->74164A7E->755E496D
Function netapi32.dll:NetGetDCName (151) intercepted, method ProcAddressHijack.GetProcAddress ->74164A97->755E5913
Function netapi32.dll:NetGetDisplayInformationIndex (152) intercepted, method ProcAddressHijack.GetProcAddress ->74164AAD->74124117
Function netapi32.dll:NetGetJoinInformation (153) intercepted, method ProcAddressHijack.GetProcAddress ->74164AD2->74132DC7
Function netapi32.dll:NetGetJoinableOUs (154) intercepted, method ProcAddressHijack.GetProcAddress ->74164AEF->741359D1
Function netapi32.dll:NetGroupAdd (155) intercepted, method ProcAddressHijack.GetProcAddress ->74164B08->741271C3
Function netapi32.dll:NetGroupAddUser (156) intercepted, method ProcAddressHijack.GetProcAddress ->74164B1B->741273AD
Function netapi32.dll:NetGroupDel (157) intercepted, method ProcAddressHijack.GetProcAddress ->74164B32->741273CB
Function netapi32.dll:NetGroupDelUser (158) intercepted, method ProcAddressHijack.GetProcAddress ->74164B45->741273EB
Function netapi32.dll:NetGroupEnum (159) intercepted, method ProcAddressHijack.GetProcAddress ->74164B5C->74127409
Function netapi32.dll:NetGroupGetInfo (160) intercepted, method ProcAddressHijack.GetProcAddress ->74164B70->741278C8
Function netapi32.dll:NetGroupGetUsers (161) intercepted, method ProcAddressHijack.GetProcAddress ->74164B87->74127952
Function netapi32.dll:NetGroupSetInfo (162) intercepted, method ProcAddressHijack.GetProcAddress ->74164B9F->74127C02
Function netapi32.dll:NetGroupSetUsers (163) intercepted, method ProcAddressHijack.GetProcAddress ->74164BB6->74127DAE
Function netapi32.dll:NetIsServiceAccount (164) intercepted, method ProcAddressHijack.GetProcAddress ->74164BCE->755E72D9
Function netapi32.dll:NetJoinDomain (165) intercepted, method ProcAddressHijack.GetProcAddress ->74164BEB->741354B9
Function netapi32.dll:NetLocalGroupAdd (166) intercepted, method ProcAddressHijack.GetProcAddress ->74164C00->7412875A
Function netapi32.dll:NetLocalGroupAddMember (167) intercepted, method ProcAddressHijack.GetProcAddress ->74164C18->74128886
Function netapi32.dll:NetLocalGroupAddMembers (168) intercepted, method ProcAddressHijack.GetProcAddress ->74164C36->74128E99
Function netapi32.dll:NetLocalGroupDel (169) intercepted, method ProcAddressHijack.GetProcAddress ->74164C55->741288A4
Function netapi32.dll:NetLocalGroupDelMember (170) intercepted, method ProcAddressHijack.GetProcAddress ->74164C6D->74128928
Function netapi32.dll:NetLocalGroupDelMembers (171) intercepted, method ProcAddressHijack.GetProcAddress ->74164C8B->74128EBD
Function netapi32.dll:NetLocalGroupEnum (172) intercepted, method ProcAddressHijack.GetProcAddress ->74164CAA->74128946
Function netapi32.dll:NetLocalGroupGetInfo (173) intercepted, method ProcAddressHijack.GetProcAddress ->74164CC3->74128CE4
Function netapi32.dll:NetLocalGroupGetMembers (174) intercepted, method ProcAddressHijack.GetProcAddress ->74164CDF->74122265
Function netapi32.dll:NetLocalGroupSetInfo (175) intercepted, method ProcAddressHijack.GetProcAddress ->74164CFE->74128D57
Function netapi32.dll:NetLocalGroupSetMembers (176) intercepted, method ProcAddressHijack.GetProcAddress ->74164D1A->74128E75
Function netapi32.dll:NetLogonGetTimeServiceParentDomain (177) intercepted, method ProcAddressHijack.GetProcAddress ->74164D39->755E6CE9
Function netapi32.dll:NetLogonSetServiceBits (178) intercepted, method ProcAddressHijack.GetProcAddress ->74164D65->755D603C
Function netapi32.dll:NetProvisionComputerAccount (184) intercepted, method ProcAddressHijack.GetProcAddress ->74164D85->7586F2D3
Function netapi32.dll:NetQueryDisplayInformation (185) intercepted, method ProcAddressHijack.GetProcAddress ->74164DA9->74123D87
Function netapi32.dll:NetQueryServiceAccount (186) intercepted, method ProcAddressHijack.GetProcAddress ->74164DCB->755E7249
Function netapi32.dll:NetRemoteComputerSupports (188) intercepted, method ProcAddressHijack.GetProcAddress ->74164DEB->74152160
Function netapi32.dll:NetRemoteTOD (189) intercepted, method ProcAddressHijack.GetProcAddress ->74164E0E->75B56C11
Function netapi32.dll:NetRemoveAlternateComputerName (190) intercepted, method ProcAddressHijack.GetProcAddress ->74164E22->74135C29
Function netapi32.dll:NetRemoveServiceAccount (191) intercepted, method ProcAddressHijack.GetProcAddress ->74164E48->755E7129
Function netapi32.dll:NetRenameMachineInDomain (192) intercepted, method ProcAddressHijack.GetProcAddress ->74164E69->74135751
Function netapi32.dll:NetRequestOfflineDomainJoin (208) intercepted, method ProcAddressHijack.GetProcAddress ->74164E89->7586B52F
Function netapi32.dll:NetScheduleJobAdd (209) intercepted, method ProcAddressHijack.GetProcAddress ->74164EAD->73C819D1
Function netapi32.dll:NetScheduleJobDel (210) intercepted, method ProcAddressHijack.GetProcAddress ->74164EC8->73C81AC9
Function netapi32.dll:NetScheduleJobEnum (211) intercepted, method ProcAddressHijack.GetProcAddress ->74164EE3->73C81BC1
Function netapi32.dll:NetScheduleJobGetInfo (212) intercepted, method ProcAddressHijack.GetProcAddress ->74164EFF->73C81CE1
Function netapi32.dll:NetServerAliasAdd (213) intercepted, method ProcAddressHijack.GetProcAddress ->74164F1E->75B57843
Function netapi32.dll:NetServerAliasDel (214) intercepted, method ProcAddressHijack.GetProcAddress ->74164F37->75B57A79
Function netapi32.dll:NetServerAliasEnum (215) intercepted, method ProcAddressHijack.GetProcAddress ->74164F50->75B57931
Function netapi32.dll:NetServerComputerNameAdd (216) intercepted, method ProcAddressHijack.GetProcAddress ->74164F6A->75B57411
Function netapi32.dll:NetServerComputerNameDel (217) intercepted, method ProcAddressHijack.GetProcAddress ->74164F8A->75B576FB
Function netapi32.dll:NetServerDiskEnum (218) intercepted, method ProcAddressHijack.GetProcAddress ->74164FAA->75B56559
Function netapi32.dll:NetServerEnum (219) intercepted, method ProcAddressHijack.GetProcAddress ->74164FC3->5BC12F61
Function netapi32.dll:NetServerEnumEx (220) intercepted, method ProcAddressHijack.GetProcAddress ->74164FD9->5BC12C5F
Function netapi32.dll:NetServerGetInfo (221) intercepted, method ProcAddressHijack.GetProcAddress ->74164FF1->75B53CFA
Function netapi32.dll:NetServerSetInfo (222) intercepted, method ProcAddressHijack.GetProcAddress ->74165009->75B56681
Function netapi32.dll:NetServerTransportAdd (223) intercepted, method ProcAddressHijack.GetProcAddress ->74165021->75B56851
Function netapi32.dll:NetServerTransportAddEx (224) intercepted, method ProcAddressHijack.GetProcAddress ->7416503E->75B57329
Function netapi32.dll:NetServerTransportDel (225) intercepted, method ProcAddressHijack.GetProcAddress ->7416505D->75B56A01
Function netapi32.dll:NetServerTransportEnum (226) intercepted, method ProcAddressHijack.GetProcAddress ->7416507A->75B56AD9
Function netapi32.dll:NetSessionDel (231) intercepted, method ProcAddressHijack.GetProcAddress ->74165098->75B55941
Function netapi32.dll:NetSessionEnum (232) intercepted, method ProcAddressHijack.GetProcAddress ->741650AD->75B55A11
Function netapi32.dll:NetSessionGetInfo (233) intercepted, method ProcAddressHijack.GetProcAddress ->741650C3->75B55B41
Function netapi32.dll:NetSetPrimaryComputerName (234) intercepted, method ProcAddressHijack.GetProcAddress ->741650DC->74135D31
Function netapi32.dll:NetShareAdd (235) intercepted, method ProcAddressHijack.GetProcAddress ->741650FD->75B55C81
Function netapi32.dll:NetShareCheck (236) intercepted, method ProcAddressHijack.GetProcAddress ->74165110->75B55E91
Function netapi32.dll:NetShareDel (237) intercepted, method ProcAddressHijack.GetProcAddress ->74165125->75B55F81
Function netapi32.dll:NetShareDelEx (238) intercepted, method ProcAddressHijack.GetProcAddress ->74165138->75B57B61
Function netapi32.dll:NetShareDelSticky (239) intercepted, method ProcAddressHijack.GetProcAddress ->7416514D->75B560D1
Function netapi32.dll:NetShareEnum (240) intercepted, method ProcAddressHijack.GetProcAddress ->74165166->75B53F91
Function netapi32.dll:NetShareEnumSticky (241) intercepted, method ProcAddressHijack.GetProcAddress ->7416517A->75B561C9
Function netapi32.dll:NetShareGetInfo (242) intercepted, method ProcAddressHijack.GetProcAddress ->74165194->75B5433F
Function netapi32.dll:NetShareSetInfo (243) intercepted, method ProcAddressHijack.GetProcAddress ->741651AB->75B56341
Function netapi32.dll:NetUnjoinDomain (245) intercepted, method ProcAddressHijack.GetProcAddress ->741651C2->74135641
Function netapi32.dll:NetUseAdd (247) intercepted, method ProcAddressHijack.GetProcAddress ->741651D9->74133693
Function netapi32.dll:NetUseDel (248) intercepted, method ProcAddressHijack.GetProcAddress ->741651EA->74135FA9
Function netapi32.dll:NetUseEnum (249) intercepted, method ProcAddressHijack.GetProcAddress ->741651FB->74133184
Function netapi32.dll:NetUseGetInfo (250) intercepted, method ProcAddressHijack.GetProcAddress ->7416520D->74136039
Function netapi32.dll:NetUserAdd (251) intercepted, method ProcAddressHijack.GetProcAddress ->74165222->7412464F
Function netapi32.dll:NetUserChangePassword (252) intercepted, method ProcAddressHijack.GetProcAddress ->74165234->74125A06
Function netapi32.dll:NetUserDel (253) intercepted, method ProcAddressHijack.GetProcAddress ->74165251->74124826
Function netapi32.dll:NetUserEnum (254) intercepted, method ProcAddressHijack.GetProcAddress ->74165263->741249D6
Function netapi32.dll:NetUserGetGroups (255) intercepted, method ProcAddressHijack.GetProcAddress ->74165276->74124E01
Function netapi32.dll:NetUserGetInfo (256) intercepted, method ProcAddressHijack.GetProcAddress ->7416528E->74121C60
Function netapi32.dll:NetUserGetLocalGroups (257) intercepted, method ProcAddressHijack.GetProcAddress ->741652A4->74122875
Function netapi32.dll:NetUserModalsGet (258) intercepted, method ProcAddressHijack.GetProcAddress ->741652C1->7412206B
Function netapi32.dll:NetUserModalsSet (259) intercepted, method ProcAddressHijack.GetProcAddress ->741652D9->741254AA
Function netapi32.dll:NetUserSetGroups (260) intercepted, method ProcAddressHijack.GetProcAddress ->741652F1->74125095
Function netapi32.dll:NetUserSetInfo (261) intercepted, method ProcAddressHijack.GetProcAddress ->74165309->74124D1D
Function netapi32.dll:NetValidateName (262) intercepted, method ProcAddressHijack.GetProcAddress ->7416531F->74135859
Function netapi32.dll:NetValidatePasswordPolicy (263) intercepted, method ProcAddressHijack.GetProcAddress ->74165336->74129967
Function netapi32.dll:NetValidatePasswordPolicyFree (264) intercepted, method ProcAddressHijack.GetProcAddress ->74165357->74129B6B
Function netapi32.dll:NetWkstaTransportAdd (267) intercepted, method ProcAddressHijack.GetProcAddress ->7416537C->74134E45
Function netapi32.dll:NetWkstaTransportDel (268) intercepted, method ProcAddressHijack.GetProcAddress ->74165398->74134F21
Function netapi32.dll:NetWkstaTransportEnum (269) intercepted, method ProcAddressHijack.GetProcAddress ->741653B4->74134CF9
Function netapi32.dll:NetWkstaUserEnum (270) intercepted, method ProcAddressHijack.GetProcAddress ->741653D1->74134AD1
Function netapi32.dll:NetWkstaUserGetInfo (271) intercepted, method ProcAddressHijack.GetProcAddress ->741653E9->74133280
Function netapi32.dll:NetWkstaUserSetInfo (272) intercepted, method ProcAddressHijack.GetProcAddress ->74165404->74134C15
Function netapi32.dll:NetapipBufferAllocate (273) intercepted, method ProcAddressHijack.GetProcAddress ->7416541F->741537AA
Function netapi32.dll:NetpIsRemote (289) intercepted, method ProcAddressHijack.GetProcAddress ->7416543E->7415382D
Function netapi32.dll:NetpwNameCanonicalize (296) intercepted, method ProcAddressHijack.GetProcAddress ->74165454->74151C30
Function netapi32.dll:NetpwNameCompare (297) intercepted, method ProcAddressHijack.GetProcAddress ->74165473->74151F2E
Function netapi32.dll:NetpwNameValidate (298) intercepted, method ProcAddressHijack.GetProcAddress ->7416548D->74151990
Function netapi32.dll:NetpwPathCanonicalize (299) intercepted, method ProcAddressHijack.GetProcAddress ->741654A8->7415275D
Function netapi32.dll:NetpwPathCompare (300) intercepted, method ProcAddressHijack.GetProcAddress ->741654C7->74154086
Function netapi32.dll:NetpwPathType (301) intercepted, method ProcAddressHijack.GetProcAddress ->741654E1->74152533
Function netapi32.dll:NlBindingAddServerToCache (302) intercepted, method ProcAddressHijack.GetProcAddress ->741654F8->755D61F8
Function netapi32.dll:NlBindingRemoveServerFromCache (303) intercepted, method ProcAddressHijack.GetProcAddress ->7416551B->755D5D67
Function netapi32.dll:NlBindingSetAuthInfo (304) intercepted, method ProcAddressHijack.GetProcAddress ->74165543->755D6198
1.2 Searching for kernel-mode API hooks
 Driver loaded successfully
 SDT found (RVA=1689C0)
 Kernel ntkrnlpa.exe found in memory at address 82A50000
   SDT = 82BB89C0
   KiST = 82ABF800 (401)
Functions checked: 401, intercepted: 0, restored: 0
1.3 Checking IDT and SYSENTER
 Analysis for CPU 1
 Analysis for CPU 2
CmpCallCallBacks = 00000000
 Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
 Checking not performed: extended monitoring driver (AVZPM) is not installed
 Driver loaded successfully
1.5 Checking of IRP handlers
\FileSystem\ntfs[IRP_MJ_CREATE] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_CLOSE] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_WRITE] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_EA] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_EA] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 84A861F8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_PNP] = 84A861F8 -> hook not defined
 Checking - complete
>>> C:\Windows\system32\certvert.dll HSC: suspicion for hidden autorun AppCertDlls (high degree of probability)
>> Services: potentially dangerous service allowed: TermService (@%SystemRoot%\System32\termsrv.dll,-268)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100)
Error [2, SC_EXT_ADDITEMST]
>> Services: potentially dangerous service allowed: Schedule (@%SystemRoot%\system32\schedsvc.dll,-100)
Error [2, SC_EXT_ADDITEMST]
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: administrative shares (C$, D$ ...) are enabled
Error [2, SC_EXT_ADDITEMST]
>> Security: anonymous user access is enabled
Error [2, SC_EXT_ADDITEMST]
Error [2, SC_EXT_ADDITEMST]
>> Security: sending Remote Assistant queries is enabled
 >>  Disable HDD autorun
 >>  Disable autorun from network drives
 >>  Disable CD/DVD autorun
 >>  Disable removable media autorun
System Analysis in progress

System Analysis - complete
Script commands
Add commands to script:
Additional operations:
File list