part 1
Shaba,
Incase the attachment didn't take here is the log in three parts.
Thanks,
John
GMER 1.0.15.15020 [fixit.exe.exe] -
http://www.gmer.net
Rootkit scan 2009-08-12 22:03:08
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xAA4F19AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xAA4F1A41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xAA4F1958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xAA4F196C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xAA4F1A55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xAA4F1A81]
Code 86315A26 ZwEnumerateKey
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xAA4F1AD9]
Code 8631A886 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xAA4F19EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xAA4F1B1E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xAA4F1A2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xAA4F1930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xAA4F1944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xAA4F19BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xAA4F1B5A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xAA4F1AC3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xAA4F1AAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xAA4F1A6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xAA4F1B46]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xAA4F1B32]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xAA4F1996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xAA4F1982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xAA4F1A97]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xAA4F1A19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xAA4F1B08]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xAA4F1A00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xAA4F19D4]
Code 86312B5D IofCallDriver
Code 8677E89D IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
Code 86337B2D ZwSaveKey
Code 863393D5 ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 86312B62
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 8677E8A2
.text ntoskrnl.exe!ZwSaveKey 804E42AE 5 Bytes JMP 86337B32
.text ntoskrnl.exe!ZwSaveKeyEx 804E42C2 5 Bytes JMP 863393DA
.text ntoskrnl.exe!ZwYieldExecution 80509014 7 Bytes JMP AA4F19D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80571CB4 5 Bytes JMP AA4F1A31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 805720F8 7 Bytes JMP AA4F1AB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 8057722F 5 Bytes JMP AA4F1A45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 80577FA4 7 Bytes JMP AA4F1B5E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 805783A4 5 Bytes JMP 86315A2A
PAGE ntoskrnl.exe!NtOpenProcess 80579084 5 Bytes JMP AA4F1934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80579399 7 Bytes JMP AA4F19C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8057D3BC 5 Bytes JMP AA4F19AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057E29B 5 Bytes JMP AA4F1A04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057E713 7 Bytes JMP AA4F19EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 8057FF0B 7 Bytes JMP AA4F1A9B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 80581B25 5 Bytes JMP AA4F1986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80585F1C 5 Bytes JMP 8631A88A
PAGE ntoskrnl.exe!ZwCreateProcessEx 8058AB14 7 Bytes JMP AA4F1970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 8058C39D 5 Bytes JMP AA4F1A1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 8058F45F 7 Bytes JMP AA4F1ADD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 805969F7 7 Bytes JMP AA4F1A85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 8059817B 7 Bytes JMP AA4F1A59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 805B1337 5 Bytes JMP AA4F1948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 805B1BA6 5 Bytes JMP AA4F1B22 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805C0C00 5 Bytes JMP AA4F195C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 80633D93 5 Bytes JMP AA4F199A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8065316C 5 Bytes JMP AA4F1B36 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 80653445 7 Bytes JMP AA4F1B0C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 80653D14 7 Bytes JMP AA4F1AC7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8065415B 7 Bytes JMP AA4F1A6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8065464E 5 Bytes JMP AA4F1B4A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? C:\WINDOWS\system32\drivers\sonyhcb.sys Access is denied.
.text USBPORT.SYS!DllUnload F6AFE62C 5 Bytes JMP 86FD01C8
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\spoolsv.exe[256] ntdll.dll!LdrUnloadDll 7C916C83 5 Bytes JMP 00C5000A
.text C:\WINDOWS\system32\svchost.exe[508] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 006B000A
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E60FEF
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E6006F
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E60054
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E60043
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E60F90
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E60FB2
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E60F69
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E600B1
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E60F33
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E600D6
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00E60F22
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00E60FA1
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00E60FD4
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00E60094
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00E60014
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00E60FC3
.text C:\WINDOWS\system32\svchost.exe[508] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00E60F58
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00E50036
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00E50073
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00E50025
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00E50FEF
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00E50062
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00E50000
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00E50051
.text C:\WINDOWS\system32\svchost.exe[508] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00E50FCA
.text C:\WINDOWS\system32\svchost.exe[508] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E4005D
.text C:\WINDOWS\system32\svchost.exe[508] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E40042
.text C:\WINDOWS\system32\svchost.exe[508] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E4001D
.text C:\WINDOWS\system32\svchost.exe[508] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E40000
.text C:\WINDOWS\system32\svchost.exe[508] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E40FD2
.text C:\WINDOWS\system32\svchost.exe[508] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E40FE3
.text C:\WINDOWS\system32\svchost.exe[508] WININET.dll!InternetOpenW 771BAEE5 5 Bytes JMP 00E30FD4
.text C:\WINDOWS\system32\svchost.exe[508] WININET.dll!InternetOpenA 771C575E 5 Bytes JMP 00E30FEF
.text C:\WINDOWS\system32\svchost.exe[508] WININET.dll!InternetOpenUrlA 771C5A11 5 Bytes JMP 00E30FC3
.text C:\WINDOWS\system32\svchost.exe[508] WININET.dll!InternetOpenUrlW 771D5B5A 5 Bytes JMP 00E30FB2
.text C:\WINDOWS\system32\svchost.exe[508] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00E20FEF
.text C:\WINDOWS\system32\winlogon.exe[744] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 008C000A
.text C:\WINDOWS\system32\winlogon.exe[744] ntdll.dll!LdrUnloadDll 7C916C83 5 Bytes JMP 008D000A
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 009D000A
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!LdrUnloadDll 7C916C83 5 Bytes JMP 009E000A
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E90FE5
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E90F86
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E90FA1
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryExW 7C801AF1 3 Bytes JMP 00E9006F
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryExW + 4 7C801AF5 1 Byte [84]
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E90FB2
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E90FC3
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E900B1
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E90F69
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E90F3A
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E900DD
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00E900EE
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00E9004A
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00E90FD4
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00E90096
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00E90025
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00E90014
.text C:\WINDOWS\system32\services.exe[788] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00E900C2
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 0007001E
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 0007008A
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00070FC3
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 0007006F
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 0007004A
.text C:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 0007002F
.text C:\WINDOWS\system32\services.exe[788] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00060FAD
.text C:\WINDOWS\system32\services.exe[788] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060038
.text C:\WINDOWS\system32\services.exe[788] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00060FD2
.text C:\WINDOWS\system32\services.exe[788] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[788] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0006001D
.text C:\WINDOWS\system32\services.exe[788] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060FE3
.text C:\WINDOWS\system32\services.exe[788] WININET.dll!InternetOpenW 771BAEE5 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[788] WININET.dll!InternetOpenA 771C575E 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[788] WININET.dll!InternetOpenUrlA 771C5A11 5 Bytes JMP 00050025
.text C:\WINDOWS\system32\services.exe[788] WININET.dll!InternetOpenUrlW 771D5B5A 5 Bytes JMP 00050FDE
.text C:\WINDOWS\system32\services.exe[788] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 0004000A
.text C:\WINDOWS\system32\lsass.exe[800] ntdll.dll!LdrUnloadDll 7C916C83 5 Bytes JMP 009E000A
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 013F0000
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 013F0F5C
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 013F005B
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 013F0F81
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 013F0F9E
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 013F0036
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 013F0F29
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 013F0F3A
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 013F0EE2
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 013F0F07
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 013F0ED1
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 013F0FAF
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 013F0FDB
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 013F0F4B
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 013F0011
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 013F0FC0
.text C:\WINDOWS\system32\lsass.exe[800] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 013F0F18
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 013E0036
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 013E0F8A
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 013E0011
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 013E0000
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 013E0047
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 013E0FE5
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 013E0FA5
.text C:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 013E0FC0
.text C:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 013D0051
.text C:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!system 77C293C7 5 Bytes JMP 013D0FC6
.text C:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 013D001B
.text C:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_open 77C2F566 5 Bytes JMP 013D0000
.text C:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 013D002C
.text C:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 013D0FD7
.text C:\WINDOWS\system32\lsass.exe[800] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 0136000A
.text C:\WINDOWS\system32\lsass.exe[800] WININET.dll!InternetOpenW 771BAEE5 5 Bytes JMP 013C001B
.text C:\WINDOWS\system32\lsass.exe[800] WININET.dll!InternetOpenA 771C575E 5 Bytes JMP 013C000A
.text C:\WINDOWS\system32\lsass.exe[800] WININET.dll!InternetOpenUrlA 771C5A11 5 Bytes JMP 013C0FEF
.text C:\WINDOWS\system32\lsass.exe[800] WININET.dll!InternetOpenUrlW 771D5B5A 5 Bytes JMP 013C0FDE
.text C:\WINDOWS\system32\svchost.exe[852] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 006B000A
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DF0000
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DF0F7A
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DF0065
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DF0054
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DF0F97
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DF0FB9
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DF009B
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DF0F55
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DF0F09
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DF0F24
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00DF00BD
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00DF0FA8
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00DF001B
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00DF0080
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00DF0FCA
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00DF0FE5
.text C:\WINDOWS\system32\svchost.exe[852] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00DF00AC
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00D1002C
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00D10FA8
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00D1001B
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00D1000A
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00D10FB9
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00D10FEF
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00D10FCA
.text C:\WINDOWS\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00D10047
.text C:\WINDOWS\system32\svchost.exe[852] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D00F8B
.text C:\WINDOWS\system32\svchost.exe[852] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D00F9C
.text C:\WINDOWS\system32\svchost.exe[852] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D00FC1
.text C:\WINDOWS\system32\svchost.exe[852] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D00FEF
.text C:\WINDOWS\system32\svchost.exe[852] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D00016
.text C:\WINDOWS\system32\svchost.exe[852] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D00FDE
.text C:\WINDOWS\system32\svchost.exe[852] WININET.dll!InternetOpenW 771BAEE5 5 Bytes JMP 00CF0011
.text C:\WINDOWS\system32\svchost.exe[852] WININET.dll!InternetOpenA 771C575E 5 Bytes JMP 00CF0000
.text C:\WINDOWS\system32\svchost.exe[852] WININET.dll!InternetOpenUrlA 771C5A11 5 Bytes JMP 00CF0022
.text C:\WINDOWS\system32\svchost.exe[852] WININET.dll!InternetOpenUrlW 771D5B5A 5 Bytes JMP 00CF0FDB
.text C:\WINDOWS\system32\svchost.exe[852] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00CE0FEF
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 02990000
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 02990F4D
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 02990F68
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 02990F79
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 02990F8A
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 02990FC0
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 02990F1F
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 02990067
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 029900AE
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 02990093
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 029900C9
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 02990FAF
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 02990FE5
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 02990F3C
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 02990036
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 0299001B
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 02990082
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 02980FC3
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 0298006F
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 02980FD4
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 02980FE5
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 02980054
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 02980000
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 02980FB2
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 0298002F
.text C:\WINDOWS\system32\svchost.exe[988] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02970F86
.text C:\WINDOWS\system32\svchost.exe[988] msvcrt.dll!system 77C293C7 5 Bytes JMP 02970011
.text C:\WINDOWS\system32\svchost.exe[988] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02970FBC
.text C:\WINDOWS\system32\svchost.exe[988] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02970FEF
.text C:\WINDOWS\system32\svchost.exe[988] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02970FAB
.text C:\WINDOWS\system32\svchost.exe[988] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02970000
.text C:\WINDOWS\system32\svchost.exe[988] WININET.dll!InternetOpenW 771BAEE5 5 Bytes JMP 01450FE5
.text C:\WINDOWS\system32\svchost.exe[988] WININET.dll!InternetOpenA 771C575E 5 Bytes JMP 01450000
.text C:\WINDOWS\system32\svchost.exe[988] WININET.dll!InternetOpenUrlA 771C5A11 5 Bytes JMP 01450FCA
.text C:\WINDOWS\system32\svchost.exe[988] WININET.dll!InternetOpenUrlW 771D5B5A 5 Bytes JMP 0145001D
.text C:\WINDOWS\system32\svchost.exe[988] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01330FEF
.text C:\WINDOWS\Explorer.EXE[1020] ntdll.dll!LdrUnloadDll 7C916C83 5 Bytes JMP 00D4000A
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001F0FEF
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001F0090
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001F007F
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001F0062
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001F0047
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001F0FCA
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001F0F5E
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001F0F6F
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001F00DC
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001F00C1
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 001F0F32
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 001F0FA5
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 001F000A
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 001F0F80
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 001F0036
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 001F001B
.text C:\WINDOWS\Explorer.EXE[1020] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 001F0F43
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 002D0FB9
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 002D0F7C
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 002D0FD4
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 002D0FE5
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 002D002F
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 002D000A
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 002D0F8D
.text C:\WINDOWS\Explorer.EXE[1020] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 002D0F9E
.text C:\WINDOWS\Explorer.EXE[1020] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002E0F8B
.text C:\WINDOWS\Explorer.EXE[1020] msvcrt.dll!system 77C293C7 5 Bytes JMP 002E0FA6
.text C:\WINDOWS\Explorer.EXE[1020] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002E0FD2
.text C:\WINDOWS\Explorer.EXE[1020] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002E000C
.text C:\WINDOWS\Explorer.EXE[1020] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002E0FC1
.text C:\WINDOWS\Explorer.EXE[1020] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002E0FEF
.text C:\WINDOWS\Explorer.EXE[1020] WININET.dll!InternetOpenW 771BAEE5 5 Bytes JMP 00300FDE
.text C:\WINDOWS\Explorer.EXE[1020] WININET.dll!InternetOpenA 771C575E 5 Bytes JMP 00300FEF
.text C:\WINDOWS\Explorer.EXE[1020] WININET.dll!InternetOpenUrlA 771C5A11 5 Bytes JMP 00300FC1
.text C:\WINDOWS\Explorer.EXE[1020] WININET.dll!InternetOpenUrlW 771D5B5A 5 Bytes JMP 00300014
.text C:\WINDOWS\Explorer.EXE[1020] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B90FE5