I Apologize for the late reply, been at work all day long but there they are:-
1a.
Attach.txt 15.44KB
151 downloads1b. DDS Contents:.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Jason at 23:45:03.43 on Tue 05/03/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2269 [GMT 10:00]
.
AV: McAfee VirusScan Enterprise *Enabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Jason\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?SearchSource=10&ctid=CT2776682
uSearch Page =
uSearch Bar =
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll
BHO: BrowserHelper Class: {8a9d74f9-560b-4fe7-abeb-3b2e638e5cd6} - c:\program files\sgpsa\SearchAssistant.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [GateWay] c:\program files\gravity\gateway\GateWayMain.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe"
mRun: [CPU Power Monitor] "c:\program files\asus\ai suite\aigear3\CpuPowerMonitor.exe"
mRun: [Cpu Level Up help] c:\program files\asus\ai suite\CpuLevelUpHelp.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\jason\applic~1\mozilla\firefox\profiles\eewmp6fq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft Choice Guard: ChoiceGuard@Microsoft - %profile%\extensions\ChoiceGuard@Microsoft
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-6-12 342128]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\engineserver.exe [2009-4-9 21256]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-3-14 103744]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\mcshield.exe [2009-4-9 144888]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2009-4-9 62800]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-6-12 70216]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-6-12 91640]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-6-12 43288]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2011-4-29 119272]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-3 135664]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-4-29 2218600]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys --> c:\windows\system32\drivers\Ambfilt.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-10-3 135664]
S3 IMNPF;WinPcap Packet Driver (IMNPF);c:\windows\system32\drivers\imnpf.sys [2009-12-20 27392]
S3 LycoFltr;Lycosa Keyboard;c:\windows\system32\drivers\Lycosa.sys [2010-6-10 16128]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-6-12 65224]
S3 XDva365;XDva365;\??\c:\windows\system32\xdva365.sys --> c:\windows\system32\XDva365.sys [?]
S3 XDva375;XDva375;\??\c:\windows\system32\xdva375.sys --> c:\windows\system32\XDva375.sys [?]
S3 XDva385;XDva385;\??\c:\windows\system32\xdva385.sys --> c:\windows\system32\XDva385.sys [?]
.
=============== Created Last 30 ================
.
2011-05-03 08:26:14 388096 ----a-r- c:\docume~1\jason\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-05-03 08:26:13 -------- d-----w- c:\program files\Trend Micro
2011-04-29 11:33:37 -------- d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2011-04-29 11:30:47 -------- d-----w- C:\NVIDIA
2011-04-29 11:11:29 41984 ----a-w- c:\documents and settings\jason\~WebUpdateHelper.exe
2011-04-29 10:53:33 -------- d-----w- c:\program files\Phyxion.net
2011-04-25 04:12:35 -------- d-----w- c:\docume~1\jason\locals~1\applic~1\PMB Files
2011-04-25 04:12:32 -------- d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2011-04-19 03:37:41 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-04-19 03:37:41 -------- d-----w- c:\windows\system32\wbem\Repository
2011-04-13 17:39:02 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-04-13 17:39:02 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2011-04-07 12:15:38 81920 ----a-w- c:\windows\system32\nvwddi.dll
2011-04-07 12:15:38 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-07 12:15:34 277608 ----a-w- c:\windows\system32\nvmccs.dll
2011-04-07 12:15:34 13891176 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-07 12:15:34 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-07 12:15:32 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2011-04-07 12:15:32 145000 ----a-w- c:\windows\system32\nvcolor.exe
.
==================== Find3M ====================
.
2011-04-29 11:31:36 259604 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-04-29 11:31:36 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-04-29 11:31:30 259604 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-04-08 05:14:00 944232 ----a-w- c:\windows\system32\nvdispco3220140.dll
2011-04-08 05:14:00 855656 ----a-w- c:\windows\system32\nvgenco322060.dll
2011-04-08 05:14:00 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-04-08 05:14:00 5210112 ----a-w- c:\windows\system32\nvcuda.dll
2011-04-08 05:14:00 4111232 ----a-w- c:\windows\system32\nv4_disp.dll
2011-04-08 05:14:00 2770536 ----a-w- c:\windows\system32\nvcuvid.dll
2011-04-08 05:14:00 2116894 ----a-w- c:\windows\system32\nvdata.bin
2011-04-08 05:14:00 2074216 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-04-08 05:14:00 2027008 ----a-w- c:\windows\system32\nvapi.dll
2011-04-08 05:14:00 14856192 ----a-w- c:\windows\system32\nvoglnt.dll
2011-04-08 05:14:00 13000704 ----a-w- c:\windows\system32\nvcompiler.dll
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 15:59:23 26216 ----a-w- c:\windows\system32\nvhdap32.dll
2011-03-03 15:59:16 837224 ----a-w- c:\windows\system32\nvhdagenco322040.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-17 13:51:57 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51:57 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51:57 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 12:37:38 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: ST3320620AS rev.3.AAC -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-1b
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8AF1F4F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8af257d0]; MOV EAX, [0x8af2584c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8AF5BAB8]
3 CLASSPNP[0xB8108FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\0000007a[0x8AF919E8]
5 ACPI[0xB7F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x8AF8F940]
\Driver\atapi[0x8AF508C0] -> IRP_MJ_CREATE -> 0x8AF1F4F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8AF1F33B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 23:45:49.98 ===============
2. aswMBR Contents:aswMBR version 0.9.5.247 Copyright© 2011 AVAST Software
Run date: 2011-05-03 23:48:56
-----------------------------
23:48:56.578 OS Version: Windows 5.1.2600 Service Pack 3
23:48:56.578 Number of processors: 4 586 0x170A
23:48:56.578 ComputerName: JASON-E31898904 UserName: Jason
23:48:56.875 Initialize success
23:48:58.421 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-1b
23:48:58.421 Disk 0 Vendor: ST3320620AS 3.AAC Size: 305245MB BusType: 3
23:48:58.421 Device \Driver\atapi -> DriverStartIo 8af1f33b
23:49:00.421 Disk 0 MBR read successfully
23:49:00.421 Disk 0 MBR scan
23:49:00.421 Disk 0 TDL4@MBR code has been found
23:49:00.421 Disk 0 Windows XP default MBR code found via API
23:49:00.421 Disk 0 MBR hidden
23:49:00.421 Disk 0 MBR [TDL4] **ROOTKIT**
23:49:00.421 Disk 0 trace - called modules:
23:49:00.421 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8af1f4f0]<<
23:49:00.421 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8af5bab8]
23:49:00.421 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\0000007a[0x8af919e8]
23:49:00.421 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> [0x8af8f940]
23:49:00.421 \Driver\atapi[0x8af508c0] -> IRP_MJ_CREATE -> 0x8af1f4f0
23:49:00.421 Scan finished successfully
23:49:32.406 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jason\Desktop\MBR.dat"
23:49:32.406 The log file has been saved successfully to "C:\Documents and Settings\Jason\Desktop\aswMBR.txt"
3. Contents of GMER:GMER 1.0.15.15572 -
http://www.gmer.netRootkit scan 2011-05-04 17:56:27
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort3 ST3320620AS rev.3.AAC
Running: gmer.exe; Driver: C:\DOCUME~1\Jason\LOCALS~1\Temp\pgxdipod.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateFile [0xB7DBD238]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB7DBD0F6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcess [0xB7DBD090]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB7DBD0A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB7DBD10A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB7DBD136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB7DBD1A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB7DBD18E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwLoadKey2 [0xB7DBD1BA]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB7DBD278]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB7DBD1E6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB7DBD0E2]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB7DBD054]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB7DBD068]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB7DBD24C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryKey [0xB7DBD222]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB7DBD178]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB7DBD162]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB7DBD120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwReplaceKey [0xB7DBD20E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRestoreKey [0xB7DBD1FA]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetContextThread [0xB7DBD0CE]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB7DBD0BA]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB7DBD14C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB7DBD2A7]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnloadKey [0xB7DBD1D0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB7DBD28E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB7DBD262]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtCreateFile
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B7DBD266 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 805790A8 5 Bytes JMP B7DBD23C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B203A 7 Bytes JMP B7DBD27C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E48 5 Bytes JMP B7DBD292 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B841E 7 Bytes JMP B7DBD250 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB440 5 Bytes JMP B7DBD058 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6CC 5 Bytes JMP B7DBD06C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE8A 5 Bytes JMP B7DBD0BE mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D117A 7 Bytes JMP B7DBD0A8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D1230 5 Bytes JMP B7DBD094 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D173A 5 Bytes JMP B7DBD0D2 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29E2 5 Bytes JMP B7DBD2AB mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 80622314 7 Bytes JMP B7DBD166 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80622662 7 Bytes JMP B7DBD150 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 8062298C 7 Bytes JMP B7DBD1D4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 8062323E 7 Bytes JMP B7DBD17C mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80623B12 7 Bytes JMP B7DBD124 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806240F0 5 Bytes JMP B7DBD0FA mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8062458C 7 Bytes JMP B7DBD10E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8062475C 7 Bytes JMP B7DBD13A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 8062493C 7 Bytes JMP B7DBD1A8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 80624BA6 7 Bytes JMP B7DBD192 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 806254CE 5 Bytes JMP B7DBD0E6 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80625810 7 Bytes JMP B7DBD226 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 80625AD0 5 Bytes JMP B7DBD1FE mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwLoadKey2 80625F20 7 Bytes JMP B7DBD1BE mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 806261C4 5 Bytes JMP B7DBD212 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 806262DE 5 Bytes JMP B7DBD1EA mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB5ECA3A0, 0x83C195, 0xE8000020]
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xA58A9A00]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0FE5
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0F72
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF0F83
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0051
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0F94
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF0FB9
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF00A9
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF008C
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF00F0
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF00DF
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF0F3C
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0040
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF000A
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF0F61
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF001B
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\svchost.exe[472] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF00BA
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00800FDE
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00800F97
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00800025
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0080004A
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00800FB2
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [A0, 88]
.text C:\WINDOWS\system32\svchost.exe[472] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00800FCD
.text C:\WINDOWS\system32\svchost.exe[472] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 007F0F8B
.text C:\WINDOWS\system32\svchost.exe[472] msvcrt.dll!system 77C293C7 5 Bytes JMP 007F0FA6
.text C:\WINDOWS\system32\svchost.exe[472] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 007F0FC1
.text C:\WINDOWS\system32\svchost.exe[472] msvcrt.dll!_open 77C2F566 5 Bytes JMP 007F0FE3
.text C:\WINDOWS\system32\svchost.exe[472] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 007F0016
.text C:\WINDOWS\system32\svchost.exe[472] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 007F0FD2
.text C:\WINDOWS\system32\svchost.exe[472] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 007E0025
.text C:\WINDOWS\system32\svchost.exe[472] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 007E000A
.text C:\WINDOWS\system32\svchost.exe[472] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 007E0FE3
.text C:\WINDOWS\system32\svchost.exe[472] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 007E0036
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01220FE5
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01220F79
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0122006E
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01220F94
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01220047
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0122001B
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01220090
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0122007F
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 012200BC
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 012200AB
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01220F12
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01220036
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01220FD4
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01220F54
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01220FB9
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01220000
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01220F2D
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0121004A
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01210FA1
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01210FEF
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0121001B
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01210FB2
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01210000
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01210FCD
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [41, 89]
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01210FDE
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01200FD2
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!system 77C293C7 5 Bytes JMP 01200053
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01200038
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01200000
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01200FE3
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0120001D
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 011F000A
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 011F0FEF
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 011F0025
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 011F0042
.text C:\WINDOWS\system32\services.exe[996] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E70FEF
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E70F52
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E70047
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E70036
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E70025
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E70F8D
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E70EFF
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E70F26
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E70EC2
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E70ED3
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E70076
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E70014
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E70FCA
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E70F37
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E70F9E
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E70FAF
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E70EEE
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E60036
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E60080
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E60FE5
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E6001B
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E60FC3
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E60000
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00E6005B
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E60FD4
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E5005F
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E5004E
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E50018
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E50FEF
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E50033
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E50FDE
.text C:\WINDOWS\system32\lsass.exe[1008] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D70FEF
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 00DC0000
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 00DC0FE5
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 00DC001D
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 00DC0FCA
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D50FE5
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D50027
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D50016
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D50F3C
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExA 7C801D53 1 Byte [E9]
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D50F57
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D50F83
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D50EE9
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D50EFA
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D50082
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D50067
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D50EC4
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D50F72
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D50FCA
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D50F17
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D50FA8
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D50FB9
.text C:\WINDOWS\system32\svchost.exe[1216] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D5004C
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D40025
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D40F94
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D4000A
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D40FDE
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D40051
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D40FEF
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D40FB9
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F4, 88]
.text C:\WINDOWS\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D40040
.text C:\WINDOWS\system32\svchost.exe[1216] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D30055
.text C:\WINDOWS\system32\svchost.exe[1216] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D30044
.text C:\WINDOWS\system32\svchost.exe[1216] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D30029
.text C:\WINDOWS\system32\svchost.exe[1216] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D30FEF
.text C:\WINDOWS\system32\svchost.exe[1216] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D30FD4
.text C:\WINDOWS\system32\svchost.exe[1216] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D30018
.text C:\WINDOWS\system32\svchost.exe[1216] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 00800014
.text C:\WINDOWS\system32\svchost.exe[1216] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 00800025
.text C:\WINDOWS\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 00800042
.text C:\WINDOWS\system32\svchost.exe[1216] WS2_32.dll!socket 71AB4211 5 Bytes JMP 007F0FEF
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F30FEF
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F30F68
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F3005D
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F30040
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F3002F
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F30FA8
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F30F1F
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F30F30
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F3009A
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F30089
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F300B5
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F30F97
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F3000A
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F30F4D
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F30FC3
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F30FD4
.text C:\WINDOWS\system32\svchost.exe[1284] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F30078
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F2002C
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F20FAF
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F20FE5
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F20011
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F20FC0
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F20000
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00F20062
.text C:\WINDOWS\system32\svchost.exe[1284] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F20051
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F10FB4
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F1003F
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F1002E
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F10FD9
.text C:\WINDOWS\system32\svchost.exe[1284] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F1001D
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 00F0001B
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 00F0000A
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 00F0002C
.text C:\WINDOWS\system32\svchost.exe[1284] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 00F0003D
.text C:\WINDOWS\system32\svchost.exe[1284] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00EF0FEF
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00800058
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00800F63
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00800F80
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00800F91
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0080002C
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0080009F
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00800084
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008000DC
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 008000C1
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00800F28
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0080003D
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00800FE5
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00800069
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00800FCA
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0080001B
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 008000B0
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 007D002F
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 007D0F8A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 007D0FDE
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 007D0FEF
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 007D0051
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 007D0000
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 007D0040
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 007D0FB9
.text C:\WINDOWS\system32\svchost.exe[1400] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 007C0051
.text C:\WINDOWS\system32\svchost.exe[1400] msvcrt.dll!system 77C293C7 5 Bytes JMP 007C0036
.text C:\WINDOWS\system32\svchost.exe[1400] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 007C0FC6
.text C:\WINDOWS\system32\svchost.exe[1400] msvcrt.dll!_open 77C2F566 5 Bytes JMP 007C0000
.text C:\WINDOWS\system32\svchost.exe[1400] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 007C001B
.text C:\WINDOWS\system32\svchost.exe[1400] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 007C0FE3
.text C:\WINDOWS\system32\svchost.exe[1400] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 007B000A
.text C:\WINDOWS\system32\svchost.exe[1400] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 007B0FEF
.text C:\WINDOWS\system32\svchost.exe[1400] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 007B001B
.text C:\WINDOWS\system32\svchost.exe[1400] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 007B002C
.text C:\WINDOWS\system32\svchost.exe[1400] WS2_32.dll!socket 71AB4211 5 Bytes JMP 007A0000
.text C:\WINDOWS\System32\svchost.exe[1444] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\System32\svchost.exe[1444] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B8000A
.text C:\WINDOWS\System32\svchost.exe[1444] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0080000C
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 05820000
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 05820F30
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 05820025
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 05820F4B
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 05820F68
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 05820F9E
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 05820F15
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0582005B
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 05820ED5
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 05820EFA
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 05820089
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 05820F83
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 05820FE5
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0582004A
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 05820FC3
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 05820FD4
.text C:\WINDOWS\System32\svchost.exe[1444] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 05820078
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 053B001B
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 053B004E
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 053B0FCA
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 053B000A
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 053B003D
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 053B0FEF
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 053B002C
.text C:\WINDOWS\System32\svchost.exe[1444] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 053B0FA5
.text C:\WINDOWS\System32\svchost.exe[1444] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00C4000A
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!_wsystem 77C2931E 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 053A0022
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!system 77C293C7 5 Bytes JMP 053A0F97
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 053A0011
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!_open 77C2F566 5 Bytes JMP 053A0FE3
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 053A0FBC
.text C:\WINDOWS\System32\svchost.exe[1444] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 053A0000
.text C:\WINDOWS\System32\svchost.exe[1444] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 02660025
.text C:\WINDOWS\System32\svchost.exe[1444] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 02660000
.text C:\WINDOWS\System32\svchost.exe[1444] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 02660036
.text C:\WINDOWS\System32\svchost.exe[1444] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 02660FEF
.text C:\WINDOWS\System32\svchost.exe[1444] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02650FEF
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01030000
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01030F68
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0103005D
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01030F83
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01030040
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01030FB9
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01030089
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01030F4D
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 010300C9
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01030F30
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01030F1F
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01030F94
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01030FE5
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01030078
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01030FCA
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01030025
.text C:\WINDOWS\system32\wuauclt.exe[1572] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 010300A4
.text C:\WINDOWS\system32\wuauclt.exe[1572] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0101003D
.text C:\WINDOWS\system32\wuauclt.exe[1572] msvcrt.dll!system 77C293C7 5 Bytes JMP 01010022
.text C:\WINDOWS\system32\wuauclt.exe[1572] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01010011
.text C:\WINDOWS\system32\wuauclt.exe[1572] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01010FEF
.text C:\WINDOWS\system32\wuauclt.exe[1572] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01010FBC
.text C:\WINDOWS\system32\wuauclt.exe[1572] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01010000
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01020011
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01020F94
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01020000
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01020FCA
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01020051
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01020FE5
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0102002C
.text C:\WINDOWS\system32\wuauclt.exe[1572] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01020FA5
.text C:\WINDOWS\system32\wuauclt.exe[1572] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 01000FEF
.text C:\WINDOWS\system32\wuauclt.exe[1572] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 0100000A
.text C:\WINDOWS\system32\wuauclt.exe[1572] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 01000FDE
.text C:\WINDOWS\system32\wuauclt.exe[1572] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 01000031
.text C:\WINDOWS\system32\wuauclt.exe[1572] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0FE5
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009B0FEF
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009B0098
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009B007D
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009B006C
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009B0FAF
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009B0040
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009B00BA
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009B00A9
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009B0F4D
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009B00E6
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009B0101
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009B0051
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009B0FDE
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009B0F7E
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009B002F
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009B001E
.text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009B00CB
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009A0FC0
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009A0062
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009A0FDB
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009A0011
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009A0047
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009A0000
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 009A0036
.text C:\WINDOWS\system32\svchost.exe[1628] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009A0FAF
.text C:\WINDOWS\system32\svchost.exe[1628] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00800027
.text C:\WINDOWS\system32\svchost.exe[1628] msvcrt.dll!system 77C293C7 5 Bytes JMP 00800F9C
.text C:\WINDOWS\system32\svchost.exe[1628] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00800FC8
.text C:\WINDOWS\system32\svchost.exe[1628] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[1628] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00800FB7
.text C:\WINDOWS\system32\svchost.exe[1628] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0080000C
.text C:\WINDOWS\system32\svchost.exe[1628] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 007F001B
.text C:\WINDOWS\system32\svchost.exe[1628] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 007F0000
.text C:\WINDOWS\system32\svchost.exe[1628] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 007F0038
.text C:\WINDOWS\system32\svchost.exe[1628] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 007F0049
.text C:\WINDOWS\system32\svchost.exe[1628] WS2_32.dll!socket 71AB4211 5 Bytes JMP 007E0FEF
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B70000
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B70097
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B70086
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B70069
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B7004E
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B70033
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B700D4
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B700C3
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B700F6
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B70F67
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B7011B
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B70FB6
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B70FE5
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B700B2
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B70022
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B70011
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B700E5
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00800FC3
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00800065
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00800FD4
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00800FE5
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00800054
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00800000
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00800043
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00800FB2
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 007F0031
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!system 77C293C7 5 Bytes JMP 007F0FA6
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 007F0FD2
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_open 77C2F566 5 Bytes JMP 007F0FEF
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 007F0FB7
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 007F000C
.text C:\WINDOWS\system32\svchost.exe[1764] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 007E0FD4
.text C:\WINDOWS\system32\svchost.exe[1764] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 007E0FEF
.text C:\WINDOWS\system32\svchost.exe[1764] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 007E000A
.text C:\WINDOWS\system32\svchost.exe[1764] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 007E0FAD
.text C:\WINDOWS\system32\svchost.exe[1764] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\Explorer.EXE[1896] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FF000A
.text C:\WINDOWS\Explorer.EXE[1896] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0118000A
.text C:\WINDOWS\Explorer.EXE[1896] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00FE000C
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D30000
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D3007D
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D3006C
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D3005B
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D30F9E
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D30040
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D3009F
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D3008E
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D30F17
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D300BA
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D300CB
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D30FB9
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D30025
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D30F63
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D30FD4
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D30FEF
.text C:\WINDOWS\Explorer.EXE[1896] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D30F3C
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D20FDE
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D20065
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D20025
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D20FEF
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D2004A
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D20000
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D20FA8
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F2, 88]
.text C:\WINDOWS\Explorer.EXE[1896] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D20FC3
.text C:\WINDOWS\Explorer.EXE[1896] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D1004C
.text C:\WINDOWS\Explorer.EXE[1896] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D10FC1
.text C:\WINDOWS\Explorer.EXE[1896] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D10FD2
.text C:\WINDOWS\Explorer.EXE[1896] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D10FEF
.text C:\WINDOWS\Explorer.EXE[1896] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D10027
.text C:\WINDOWS\Explorer.EXE[1896] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D1000C
.text C:\WINDOWS\Explorer.EXE[1896] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 00D00FE5
.text C:\WINDOWS\Explorer.EXE[1896] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 00D00000
.text C:\WINDOWS\Explorer.EXE[1896] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 00D00011
.text C:\WINDOWS\Explorer.EXE[1896] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 00D00FCA
.text C:\WINDOWS\Explorer.EXE[1896] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00CF0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01680FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01680039
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01680F44
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01680F55
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01680F72
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01680F9E
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01680F11
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01680F22
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01680EC0
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01680ED1
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01680EA5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01680F8D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01680FD4
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01680F33
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01680FB9
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0168000A
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01680EEC
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00810FA5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00810036
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00810000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00810FD4
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00810F79
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00810FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0081001B
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00810F8A
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0080004E
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] msvcrt.dll!system 77C293C7 5 Bytes JMP 00800033
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00800018
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00800FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00800FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00800FDE
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] WS2_32.dll!socket 71AB4211 5 Bytes JMP 007E0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 007F0FDB
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 007F0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 007F0011
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[2592] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 007F002C
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00830FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00830064
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00830053
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00830F79
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00830F8A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00830FAF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00830F4D
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00830F5E
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008300BA
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00830F21
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 008300CB
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00830036
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00830FD4
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0083007F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0083001B
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00830000
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00830F32
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00820FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00820F97
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0082002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00820FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00820FB2
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00820000
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00820FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [A2, 88]
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0082004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00810FB7
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] msvcrt.dll!system 77C293C7 5 Bytes JMP 00810FC8
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0081001D
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00810FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00810038
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0081000C
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] WS2_32.dll!socket 71AB4211 5 Bytes JMP 007F0000
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] WININET.dll!InternetOpenW 771BAF55 5 Bytes JMP 0080001B
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] WININET.dll!InternetOpenA 771C57A6 5 Bytes JMP 0080000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] WININET.dll!InternetOpenUrlA 771C5A72 5 Bytes JMP 00800036
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3408] WININET.dll!InternetOpenUrlW 771D5BC2 5 Bytes JMP 00800FE5
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-4 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T1L0-c 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort4 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort5 8AEDC33B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP3T0L0-1b 8AEDC33B
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- EOF - GMER 1.0.15 ----