GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-06-02 08:45:04
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\drivers\37acc36.sys ZwCreateEvent [0xB9C6432D]
SSDT \SystemRoot\System32\drivers\37acc36.sys ZwCreateKey [0xB9C62405]
SSDT \SystemRoot\System32\drivers\37acc36.sys ZwOpenKey [0xB9C624C5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB04CA9AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB04CA958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB04CA96C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB04CAA5D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB04CAA89]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB04CAAF7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB04CAAE1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB04CA9EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB04CAB23]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB04CA930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB04CA944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB04CA9BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xB04CAB5F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB04CAACB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB04CAAB5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB04CAA73]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xB04CAB4B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xB04CAB37]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB04CA996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB04CA982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xB04CAA9F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB04CAA19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xB04CAB0D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB04CAA00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB04CA9D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 805021FC 7 Bytes JMP B04CA9D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8056DF7C 5 Bytes JMP B04CA9AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805A70D8 7 Bytes JMP B04CA9EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A7EEE 5 Bytes JMP B04CAA04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805AD66C 7 Bytes JMP B04CA9C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805C0DD4 5 Bytes JMP B04CA934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805C1060 5 Bytes JMP B04CA948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805C3892 5 Bytes JMP B04CA986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C6E8E 7 Bytes JMP B04CA970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805C6F44 5 Bytes JMP B04CA95C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805C744E 5 Bytes JMP B04CA99A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805C8724 5 Bytes JMP B04CAA1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 80617F30 7 Bytes JMP B04CAAB9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8061827E 5 Bytes JMP B04CAB3B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80618536 7 Bytes JMP B04CAAA3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 806187FE 7 Bytes JMP B04CAB11 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 80619044 7 Bytes JMP B04CAACF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 8061989C 7 Bytes JMP B04CAA77 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8061A306 7 Bytes JMP B04CAA61 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8061A4D6 7 Bytes JMP B04CAA8D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 8061A6B6 7 Bytes JMP B04CAAFB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8061A920 7 Bytes JMP B04CAAE5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 8061B530 7 Bytes JMP B04CAB63 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8061BA56 5 Bytes JMP B04CAB4F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8061BB70 5 Bytes JMP B04CAB27 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\System32\drivers\37acc36.sys The system cannot find the file specified.
---- User code sections - GMER 1.0.15 ----
C:\Documents and Settings\Owner\My Documents\My Received Files\My Torrents\winlogon.exe[148] C:\Documents and Settings\Owner\My Documents\My Received Files\My Torrents\winlogon.exe entry point in "" section [0x00525D48]
.rsrc C:\Documents and Settings\Owner\My Documents\My Received Files\My Torrents\winlogon.exe[148] C:\Documents and Settings\Owner\My Documents\My Received Files\My Torrents\winlogon.exe section is executable [0x00551000, 0x53B00, 0xE0000040]
.mackt C:\Documents and Settings\Owner\My Documents\My Received Files\My Torrents\winlogon.exe[148] C:\Documents and Settings\Owner\My Documents\My Received Files\My Torrents\winlogon.exe unknown last code section [0x005D4000, 0x3000, 0xE0000060]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[192] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[192] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01110FEF
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01110F85
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01110FA0
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0111007A
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01110069
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01110047
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01110F4F
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 01110095
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01110F12
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01110F23
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 011100D0
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 01110058
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 0111000A
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 01110F6A
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 01110036
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateNamedPipeA 7C85FE94 3 Bytes JMP 01110025
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!CreateNamedPipeA + 4 7C85FE98 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[372] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 01110F3E
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 010F0FAF
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 010F0062
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 010F0FCA
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 010F0FE5
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 010F0051
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 010F000A
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 010F0040
.text C:\WINDOWS\system32\svchost.exe[372] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 010F0025
.text C:\WINDOWS\system32\svchost.exe[372] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 010E006E
.text C:\WINDOWS\system32\svchost.exe[372] msvcrt.dll!system 77C293C7 5 Bytes JMP 010E0FE3
.text C:\WINDOWS\system32\svchost.exe[372] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 010E0038
.text C:\WINDOWS\system32\svchost.exe[372] msvcrt.dll!_open 77C2F566 5 Bytes JMP 010E0000
.text C:\WINDOWS\system32\svchost.exe[372] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 010E0053
.text C:\WINDOWS\system32\svchost.exe[372] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 010E0011
.text C:\WINDOWS\system32\svchost.exe[372] Ws2_32.dll!socket 71AB3B91 5 Bytes JMP 010D0000
.text C:\WINDOWS\system32\svchost.exe[372] Wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 0110000A
.text C:\WINDOWS\system32\svchost.exe[372] Wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 01100025
.text C:\WINDOWS\system32\svchost.exe[372] Wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 01100036
.text C:\WINDOWS\system32\svchost.exe[372] Wininet.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 01100FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00250000
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00250F57
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00250F68
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00250F83
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00250F94
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00250036
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00250F15
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0025005D
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00250ECE
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00250EE9
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00250EBD
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00250FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00250FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00250F3C
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 0025001B
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00250FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[568] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00250EFA
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00330F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00330F61
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00330FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00330FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00330F72
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00330FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 00330F83
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [53, 88]
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 0033000A
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 408BF341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 40A51777 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 40A516F8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 40A5173C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 40A51684 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 40A516BE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 40A517B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 408E16B6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[568] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00340F64
.text C:\Program Files\Internet Explorer\iexplore.exe[568] msvcrt.dll!system 77C293C7 5 Bytes JMP 00340F7F
.text C:\Program Files\Internet Explorer\iexplore.exe[568] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00340FB5
.text C:\Program Files\Internet Explorer\iexplore.exe[568] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00340FE3
.text C:\Program Files\Internet Explorer\iexplore.exe[568] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00340F9A
.text C:\Program Files\Internet Explorer\iexplore.exe[568] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00340FC6
.text C:\Program Files\Internet Explorer\iexplore.exe[568] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 019C000A
.text C:\Program Files\Internet Explorer\iexplore.exe[568] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 019C001B
.text C:\Program Files\Internet Explorer\iexplore.exe[568] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 019C002C
.text C:\Program Files\Internet Explorer\iexplore.exe[568] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 019C0FD1
.text C:\Program Files\Internet Explorer\iexplore.exe[568] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 02920FEF
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00070FA6
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070FB7
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00070091
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00070076
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00070040
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 000700E4
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 000700D3
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00070110
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 000700F5
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00070F5C
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0007005B
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00070FE5
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 000700B6
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 0007002F
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[576] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00070F81
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0006000A
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00060F54
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00060FC3
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00060FD4
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00060F6F
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00060FE5
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 0006001B
.text C:\WINDOWS\system32\services.exe[576] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 00060F94
.text C:\WINDOWS\system32\services.exe[576] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00050FAF
.text C:\WINDOWS\system32\services.exe[576] msvcrt.dll!system 77C293C7 5 Bytes JMP 00050044
.text C:\WINDOWS\system32\services.exe[576] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00050FDE
.text C:\WINDOWS\system32\services.exe[576] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[576] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00050029
.text C:\WINDOWS\system32\services.exe[576] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0005000C
.text C:\WINDOWS\system32\services.exe[576] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00EA0FEF
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00EA0065
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00EA0054
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00EA0F70
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00EA0039
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00EA0FB2
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00EA00A4
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00EA0087
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00EA0F30
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00EA0F41
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00EA00E4
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00EA0F8D
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00EA0FDE
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00EA0076
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00EA001E
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00EA0FCD
.text C:\WINDOWS\system32\lsass.exe[588] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00EA00BF
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E9002F
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E90F8D
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E90FDE
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E9000A
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00E9004A
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00E90FEF
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 00E90FA8
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [09, 89]
.text C:\WINDOWS\system32\lsass.exe[588] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 00E90FB9
.text C:\WINDOWS\system32\lsass.exe[588] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E80053
.text C:\WINDOWS\system32\lsass.exe[588] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E80042
.text C:\WINDOWS\system32\lsass.exe[588] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E80027
.text C:\WINDOWS\system32\lsass.exe[588] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\lsass.exe[588] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E80FD2
.text C:\WINDOWS\system32\lsass.exe[588] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E80000
.text C:\WINDOWS\system32\lsass.exe[588] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00E70000
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C10FEF
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C1006F
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C10054
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C10F86
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C10F97
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C10039
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C1009B
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C10F55
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C10F1D
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C10F38
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00C100C7
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00C10FB2
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00C1000A
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00C10080
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00C10FC3
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00C10FDE
.text C:\WINDOWS\system32\svchost.exe[760] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00C100AC
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C00FC3
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C00F7C
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C0001E
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C00FDE
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00C00F8D
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00C00FEF
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 00C0002F
.text C:\WINDOWS\system32\svchost.exe[760] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 00C00FB2
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BF0FAD
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BF002E
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BF001D
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BF0FC8
.text C:\WINDOWS\system32\svchost.exe[760] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BF000C
.text C:\WINDOWS\system32\svchost.exe[760] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00870000
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00870F74
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00870F85
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00870FA2
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0087005F
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0087003D
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00870F34
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00870F4F
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008700CD
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008700B2
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00870F19
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0087004E
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00870FE5
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 0087007A
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 0087002C
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 0087001B
.text C:\WINDOWS\system32\svchost.exe[824] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 008700A1
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00860FCA
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00860F68
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00860FDB
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0086001B
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00860F79
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00860000
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 00860F9E
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [A6, 88]
.text C:\WINDOWS\system32\svchost.exe[824] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 00860FB9
.text C:\WINDOWS\system32\svchost.exe[824] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00850FA8
.text C:\WINDOWS\system32\svchost.exe[824] msvcrt.dll!system 77C293C7 5 Bytes JMP 00850FB9
.text C:\WINDOWS\system32\svchost.exe[824] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00850FD4
.text C:\WINDOWS\system32\svchost.exe[824] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0085000C
.text C:\WINDOWS\system32\svchost.exe[824] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00850033
.text C:\WINDOWS\system32\svchost.exe[824] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00850FEF
.text C:\WINDOWS\system32\svchost.exe[824] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 0084000A
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 024D0FEF
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 024D007B
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 024D0F90
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 024D006A
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 024D0FA1
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 024D0FB2
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 024D0F55
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 024D009D
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 024D00E7
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 024D00CC
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 024D0F33
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 024D0043
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 024D0014
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 024D008C
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 024D0FCD
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 024D0FDE
.text C:\WINDOWS\System32\svchost.exe[888] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 024D0F44
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 024B0FCA
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 024B0076
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 024B001B
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 024B000A
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 024B0065
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 024B0FEF
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 024B0040
.text C:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 024B0FB9
.text C:\WINDOWS\System32\svchost.exe[888] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 024A0FAB
.text C:\WINDOWS\System32\svchost.exe[888] msvcrt.dll!system 77C293C7 5 Bytes JMP 024A0FBC
.text C:\WINDOWS\System32\svchost.exe[888] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 024A0011
.text C:\WINDOWS\System32\svchost.exe[888] msvcrt.dll!_open 77C2F566 5 Bytes JMP 024A0FE3
.text C:\WINDOWS\System32\svchost.exe[888] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 024A0022
.text C:\WINDOWS\System32\svchost.exe[888] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 024A0000
.text C:\WINDOWS\System32\svchost.exe[888] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 0248000A
.text C:\WINDOWS\System32\svchost.exe[888] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 024C0000
.text C:\WINDOWS\System32\svchost.exe[888] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 024C0011
.text C:\WINDOWS\System32\svchost.exe[888] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 024C0FD1
.text C:\WINDOWS\System32\svchost.exe[888] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 024C0FC0
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00280FEF
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00280067
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00280056
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00280045
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00280F7C
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00280FA8
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00280F3C
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00280084
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00280F06
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00280F21
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 002800B0
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00280F97
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00280FDE
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00280F57
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 0028001E
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00280FCD
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 0028009F
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0027001E
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00270F72
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00270FCD
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00270FDE
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00270F83
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00270FEF
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 00270FA8
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [47, 88]
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 0027002F
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0026000C
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!system 77C293C7 5 Bytes JMP 00260F8B
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00260FB7
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00260FE3
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00260F9C
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00260FD2
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00790000
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00790F68
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00790F79
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00790047
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00790F8A
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00790FAC
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00790F30
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00790078
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00790EFA
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00790F0B
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00790EE9
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00790F9B
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00790011
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00790F4D
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00790FC7
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00790022
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00790089
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00780FCA
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00780058
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0078001B
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00780FE5
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00780047
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00780000
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 00780FAF
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [98, 88]
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 0078002C
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00770050
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!system 77C293C7 5 Bytes JMP 0077003F
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0077001D
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00770FE3
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0077002E
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00770000
.text C:\WINDOWS\system32\svchost.exe[1108] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 0076000A
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00190FEF
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00190049
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00190038
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00190F5E
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0019001B
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00190F94
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00190F23
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0019006B
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001900B5
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00190090
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00190EF7
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00190F83
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00190FCA
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 0019005A
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00190FA5
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00190000
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00190F12
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00270FD1
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0027005F
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00270022
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00270011
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 0027004E
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00270000
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 00270FAC
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [47, 88]
.text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 0027003D
.text C:\WINDOWS\System32\svchost.exe[1132] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0028003F
.text C:\WINDOWS\System32\svchost.exe[1132] msvcrt.dll!system 77C293C7 5 Bytes JMP 0028002E
.text C:\WINDOWS\System32\svchost.exe[1132] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00280FD9
.text C:\WINDOWS\System32\svchost.exe[1132] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00280000
.text C:\WINDOWS\System32\svchost.exe[1132] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00280FBE
.text C:\WINDOWS\System32\svchost.exe[1132] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00280011
.text C:\WINDOWS\System32\svchost.exe[1132] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 005B0000
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00810FEF
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00810F8B
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00810080
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0081006F
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00810FB2
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00810039
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008100AC
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0081009B
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008100E9
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008100CE
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00810F35
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0081005E
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00810014
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00810F7A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00810FCD
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00810FDE
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 008100BD
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0080002F
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00800FA5
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00800FD4
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00800014
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 0080006C
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 00800051
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 00800040
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 007F0FA6
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!system 77C293C7 5 Bytes JMP 007F003B
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 007F0FD2
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 007F0000
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 007F0FC1
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 007F0FE3
.text C:\WINDOWS\system32\svchost.exe[1188] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007E0FEF
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00980FE5
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00980F65
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0098005A
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00980F80
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00980033
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00980011
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00980088
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00980077
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00980EF9
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00980F0A
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 009800B7
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00980022
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00980FD4
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00980F40
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00980FA5
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00980000
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00980F1B
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00970FB9
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00970F83
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00970FCA
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00970000
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00970040
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00970FEF
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 00970025
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 00970F9E
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 007D0FC3
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!system 77C293C7 5 Bytes JMP 007D0044
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 007D0018
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_open 77C2F566 5 Bytes JMP 007D0FEF
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 007D0029
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 007D0FDE
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 014E0000
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 014E009E
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 014E0079
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 014E0FAB
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 014E0FBC
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 014E0FDE
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 014E00C0
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 014E0F84
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 014E0F67
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 014E00F6
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 014E0F4C
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 014E0FCD
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 014E0FEF
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 014E00AF
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 014E0040
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 014E0025
.text C:\WINDOWS\Explorer.EXE[1356] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 014E00DB
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 014C001B
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 014C004A
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 014C000A
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 014C0FCA
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 014C0F97
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 014C0FEF
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 2 Bytes JMP 014C0FA8
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA40 2 Bytes [6C, 89]
.text C:\WINDOWS\Explorer.EXE[1356] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 014C0FB9
.text C:\WINDOWS\Explorer.EXE[1356] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01340069
.text C:\WINDOWS\Explorer.EXE[1356] msvcrt.dll!system 77C293C7 5 Bytes JMP 0134004E
.text C:\WINDOWS\Explorer.EXE[1356] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01340FDE
.text C:\WINDOWS\Explorer.EXE[1356] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01340FEF
.text C:\WINDOWS\Explorer.EXE[1356] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0134003D
.text C:\WINDOWS\Explorer.EXE[1356] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0134000C
.text C:\WINDOWS\Explorer.EXE[1356] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 014D0000
.text C:\WINDOWS\Explorer.EXE[1356] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 014D0FE5
.text C:\WINDOWS\Explorer.EXE[1356] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 014D0FD4
.text C:\WINDOWS\Explorer.EXE[1356] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 014D0FC3
.text C:\WINDOWS\Explorer.EXE[1356] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01140FEF
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00760FE5
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00760090
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0076007F
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00760FA5
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00760058
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00760036
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 007600BC
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 007600AB
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00760103
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 007600E8
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00760F59
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00760047
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 0076000A
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00760F80
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00760FCA
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 0076001B
.text C:\WINDOWS\system32\svchost.exe[1784] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 007600CD
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00520FA8
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00520F7C
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00520FB9
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00520FCA
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 5 Bytes JMP 00520F97
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 5 Bytes JMP 00520FE5
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegCreateKeyW 77DFBA3D 5 Bytes JMP 00520039
.text C:\WINDOWS\system32\svchost.exe[1784] ADVAPI32.dll!RegCreateKeyA 77DFBCDB 5 Bytes JMP 0052001E
.text C:\WINDOWS\system32\svchost.exe[1784] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0051004E
.text C:\WINDOWS\system32\svchost.exe[1784] msvcrt.dll!system 77C293C7 5 Bytes JMP 00510FC3
.text C:\WINDOWS\system32\svchost.exe[1784] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00510022
.text C:\WINDOWS\system32\svchost.exe[1784] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00510FEF
.text C:\WINDOWS\system32\svchost.exe[1784] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0051003D
.text C:\WINDOWS\system32\svchost.exe[1784] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00510FDE
.text C:\WINDOWS\system32\svchost.exe[1784] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00530000
.text C:\WINDOWS\system32\svchost.exe[1784] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00530011
.text C:\WINDOWS\system32\svchost.exe[1784] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00530022
.text C:\WINDOWS\system32\svchost.exe[1784] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00530FC7
.text C:\WINDOWS\system32\svchost.exe[1784] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00500FEF
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!GetStockObject] [6113909F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [6113909F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6113A3BF] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [61139856] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [61139856] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61138FE2] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [61138F66] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [61138FA4] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetStockObject] [6113909F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6113A3BF] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [611390DD] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61138FA4] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [61139856] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [61138FE2] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [61139856] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [611390A5] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61138F66] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE[2824] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [61139C3F] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 37acc36.sys
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip 37acc36.sys
Device \Driver\MPFP \Device\MPFP 37acc36.sys
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp 37acc36.sys
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp 37acc36.sys
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp 37acc36.sys
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\System32\drivers\37acc36.sys (*** hidden *** ) [SYSTEM] 37acc36 <-- ROOTKIT !!!
Service system32\drivers\UACkxfonwej.sys (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] \SystemRoot\System32\drivers\37acc36.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] \systemroot\system32\drivers\UACkxfonwej.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\
[email protected] file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\drivers\UACkxfonwej.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACiffccilu.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACkvtrufyt.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACapqnkprp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACkixbuxwh.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACrjwqnxwk.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UAClvdqybne.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACfypojatm.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACdrvklkjo.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACqqpxwxll.dll
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] \SystemRoot\System32\drivers\37acc36.sys
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] 1
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] 1
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] 1
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] 1
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] 1
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] \systemroot\system32\drivers\UACkxfonwej.sys
Reg HKLM\SYSTEM\ControlSet002\Services\
[email protected] file system
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\drivers\UACkxfonwej.sys
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACiffccilu.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACkvtrufyt.dat
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACapqnkprp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACkixbuxwh.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACrjwqnxwk.dll
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UAClvdqybne.log
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACfypojatm.log
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACdrvklkjo.log
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\
[email protected] \\?\globalroot\systemroot\system32\UACqqpxwxll.dll
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
---- EOF - GMER 1.0.15 ----