Zeus42
2007-07-16, 14:15
Hi
I ran vudo fix and came up clean, then ran spybot and virtumonde was still there. Here is the report from GMER
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-16 06:14:32
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
Code 865EB770 ZwCreateSection
Code 865E1E40 ZwDuplicateObject
Code 8652F1E0 ZwSetInformationFile
Code 865689C8 ZwSetSystemInformation
Code 865DCC18 ZwWriteFile
Code 865EB76F NtCreateSection
Code 865E1E3F NtDuplicateObject
Code 8652F1DF NtSetInformationFile
Code 865DCC17 NtWriteFile
---- Kernel code sections - GMER 1.0.13 ----
PAGE ntkrnlpa.exe!IoGetBootDiskInformation + 66F 8056AC95 7 Bytes JMP 8653B6DC
PAGE ntkrnlpa.exe!NtSetInformationFile 8056F398 5 Bytes JMP 8652F1E4
PAGE ntkrnlpa.exe!NtWriteFile 80571334 7 Bytes JMP 865DCC1C
PAGE ntkrnlpa.exe!NtCreateSection 8059F4EA 7 Bytes JMP 865EB774
PAGE ntkrnlpa.exe!ObCloseHandle + 17 805B09BB 7 Bytes JMP 86494A04
PAGE ntkrnlpa.exe!NtDuplicateObject 805B249C 7 Bytes JMP 865E1E44
PAGE ntkrnlpa.exe!ZwSetSystemInformation 80604932 5 Bytes JMP 865689CC
PAGE Fastfat.SYS B9912948 7 Bytes JMP 8663FE44
? C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified.
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified.
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[716] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
I ran vudo fix and came up clean, then ran spybot and virtumonde was still there. Here is the report from GMER
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-16 06:14:32
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
Code 865EB770 ZwCreateSection
Code 865E1E40 ZwDuplicateObject
Code 8652F1E0 ZwSetInformationFile
Code 865689C8 ZwSetSystemInformation
Code 865DCC18 ZwWriteFile
Code 865EB76F NtCreateSection
Code 865E1E3F NtDuplicateObject
Code 8652F1DF NtSetInformationFile
Code 865DCC17 NtWriteFile
---- Kernel code sections - GMER 1.0.13 ----
PAGE ntkrnlpa.exe!IoGetBootDiskInformation + 66F 8056AC95 7 Bytes JMP 8653B6DC
PAGE ntkrnlpa.exe!NtSetInformationFile 8056F398 5 Bytes JMP 8652F1E4
PAGE ntkrnlpa.exe!NtWriteFile 80571334 7 Bytes JMP 865DCC1C
PAGE ntkrnlpa.exe!NtCreateSection 8059F4EA 7 Bytes JMP 865EB774
PAGE ntkrnlpa.exe!ObCloseHandle + 17 805B09BB 7 Bytes JMP 86494A04
PAGE ntkrnlpa.exe!NtDuplicateObject 805B249C 7 Bytes JMP 865E1E44
PAGE ntkrnlpa.exe!ZwSetSystemInformation 80604932 5 Bytes JMP 865689CC
PAGE Fastfat.SYS B9912948 7 Bytes JMP 8663FE44
? C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified.
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified.
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[648] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[648] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[672] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[716] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[728] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[936] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1028] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]