Have run Gmer
Hi Shaba,
I have done the scan. I tried to post the results into a reply but I got a message that there were 107000 characters and the limit was 64000, so I have broken the paste of the scan into two parts, the second part will be pasted into my next reply.
I would like to use my computer online while we are going thru the process of cleaning off the viruses. Should I keep Resident Teatimer disabled and go on the web throughout the time we are conversing back and forth, or should I re-enable it between our contacting each other, and then disable it when I'm going to do your next set of instructions?
Thank you for your help, I really appreciate it!
Irwin
GMER 1.0.15.15163 -
http://www.gmer.net
Rootkit scan 2009-10-18 17:31:46
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\BRIAND~1.STU\LOCALS~1\Temp\pxtdypow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF6B644EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xF6B64581]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF6B64498]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF6B644AC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF6B64595]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF6B645C1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF6B64634]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF6B64619]
Code 82DB52F0 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF6B6452A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF6B6465E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xF6B6456D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF6B64470]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF6B64484]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF6B644FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF6B6469A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF6B64603]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF6B645ED]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF6B645AB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF6B64686]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF6B64672]
Code 82D3671E ZwSaveKey
Code 82DB535E ZwSaveKeyEx
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF6B644D6]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF6B644C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF6B645D7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF6B64559]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF6B64648]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF6B64540]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF6B64514]
Code 82D36756 IofCallDriver
Code 82DB487E IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 82D3675B
.text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 82DB4883
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80577693 5 Bytes JMP 82DB52F4
PAGE ntoskrnl.exe!ZwSaveKey 8064ED72 5 Bytes JMP 82D36722
PAGE ntoskrnl.exe!ZwSaveKeyEx 8064EE5D 5 Bytes JMP 82DB5362
PAGE ntoskrnl.exe!ZwReplaceKey + 3 8064F0DF 2 Bytes [51, 76]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01460000
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01460F5E
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01460F83
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0146005D
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01460F94
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01460025
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01460F2B
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01460F3C
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 014600BD
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01460098
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01460F09
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01460036
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01460FE5
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01460F4D
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01460FB9
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01460FCA
.text C:\WINDOWS\system32\svchost.exe[116] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01460F1A
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0144002C
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01440F83
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0144001B
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01440000
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01440F9E
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01440FE5
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01440FAF
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [64, 89]
.text C:\WINDOWS\system32\svchost.exe[116] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01440FCA
.text C:\WINDOWS\system32\svchost.exe[116] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01430033
.text C:\WINDOWS\system32\svchost.exe[116] msvcrt.dll!system 77C293C7 5 Bytes JMP 01430FB2
.text C:\WINDOWS\system32\svchost.exe[116] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01430011
.text C:\WINDOWS\system32\svchost.exe[116] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01430000
.text C:\WINDOWS\system32\svchost.exe[116] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01430022
.text C:\WINDOWS\system32\svchost.exe[116] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01430FD7
.text C:\WINDOWS\system32\svchost.exe[116] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01450FEF
.text C:\WINDOWS\system32\svchost.exe[116] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 01450FDE
.text C:\WINDOWS\system32\svchost.exe[116] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 01450FC3
.text C:\WINDOWS\system32\svchost.exe[116] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 01450FB2
.text C:\WINDOWS\system32\svchost.exe[116] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01420000
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01400FEF
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01400F41
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01400F5C
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01400040
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0140002F
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01400F9E
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01400F09
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01400F1A
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 0140007D
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0140006C
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0140008E
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01400F8D
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0140000A
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01400051
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01400FC3
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01400FD4
.text C:\WINDOWS\system32\services.exe[536] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01400EEE
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 013E0039
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 013E0F97
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 013E0FDE
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 013E0FEF
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 013E0FA8
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 013E000A
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 013E0FB9
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [5E, 89]
.text C:\WINDOWS\system32\services.exe[536] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 013E004A
.text C:\WINDOWS\system32\services.exe[536] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0F89
.text C:\WINDOWS\system32\services.exe[536] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF0F9A
.text C:\WINDOWS\system32\services.exe[536] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\services.exe[536] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0FE3
.text C:\WINDOWS\system32\services.exe[536] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0FAB
.text C:\WINDOWS\system32\services.exe[536] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0FD2
.text C:\WINDOWS\system32\services.exe[536] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 013F0000
.text C:\WINDOWS\system32\services.exe[536] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 013F0FE5
.text C:\WINDOWS\system32\services.exe[536] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 013F001B
.text C:\WINDOWS\system32\services.exe[536] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 013F002C
.text C:\WINDOWS\system32\services.exe[536] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateFileA 7C801A28 3 Bytes JMP 010C0FE5
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateFileA + 4 7C801A2C 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!VirtualProtectEx 7C801A61 3 Bytes JMP 010C0F52
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!VirtualProtectEx + 4 7C801A65 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!VirtualProtect 7C801AD4 3 Bytes JMP 010C0051
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!VirtualProtect + 4 7C801AD8 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 010C0F77
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryExA 7C801D53 3 Bytes JMP 010C0F9E
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryExA + 4 7C801D57 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryA 7C801D7B 3 Bytes JMP 010C001B
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryA + 4 7C801D7F 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!GetStartupInfoW 7C801E54 3 Bytes JMP 010C0F09
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!GetStartupInfoW + 4 7C801E58 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 010C0F1A
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateProcessW 7C802336 3 Bytes JMP 010C0087
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateProcessW + 4 7C80233A 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateProcessA 7C80236B 3 Bytes JMP 010C0EE4
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateProcessA + 4 7C80236F 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!GetProcAddress 7C80AE40 3 Bytes JMP 010C0ED3
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!GetProcAddress + 4 7C80AE44 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryW 7C80AEEB 3 Bytes JMP 010C0036
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!LoadLibraryW + 4 7C80AEEF 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateFileW 7C810800 3 Bytes JMP 010C0FCA
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateFileW + 4 7C810804 1 Byte [84]
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 010C0F37
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 010C0FB9
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 010C0000
.text C:\WINDOWS\system32\lsass.exe[548] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 010C006C
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 010A0FAF
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 010A001B
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 010A0FCA
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 010A0000
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 010A0F5E
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 010A0FEF
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 010A0F83
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [2A, 89]
.text C:\WINDOWS\system32\lsass.exe[548] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 010A0F94
.text C:\WINDOWS\system32\lsass.exe[548] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01090FAD
.text C:\WINDOWS\system32\lsass.exe[548] msvcrt.dll!system 77C293C7 5 Bytes JMP 01090038
.text C:\WINDOWS\system32\lsass.exe[548] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01090FD2
.text C:\WINDOWS\system32\lsass.exe[548] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01090000
.text C:\WINDOWS\system32\lsass.exe[548] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01090027
.text C:\WINDOWS\system32\lsass.exe[548] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01090FE3
.text C:\WINDOWS\system32\lsass.exe[548] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D70FEF
.text C:\WINDOWS\system32\lsass.exe[548] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 010B0FEF
.text C:\WINDOWS\system32\lsass.exe[548] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 010B0000
.text C:\WINDOWS\system32\lsass.exe[548] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 010B001B
.text C:\WINDOWS\system32\lsass.exe[548] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 010B0FCA
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F10FE5
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F10F8D
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F10F9E
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F10078
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F1005B
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F10FD4
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F100AE
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F10F66
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateProcessW 7C802336 1 Byte [E9]
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F10F3A
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F10F4B
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F100E4
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F10FC3
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F1000A
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F10093
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F10036
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F10025
.text C:\WINDOWS\system32\svchost.exe[700] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F100C9
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EF0FCA
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EF0051
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EF0FDB
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EF0011
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EF0F94
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EF0000
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EF0FAF
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0F, 89]
.text C:\WINDOWS\system32\svchost.exe[700] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EF0036
.text C:\WINDOWS\system32\svchost.exe[700] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EE006E
.text C:\WINDOWS\system32\svchost.exe[700] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EE0053
.text C:\WINDOWS\system32\svchost.exe[700] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EE0FD9
.text C:\WINDOWS\system32\svchost.exe[700] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EE000C
.text C:\WINDOWS\system32\svchost.exe[700] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EE0038
.text C:\WINDOWS\system32\svchost.exe[700] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EE001D
.text C:\WINDOWS\system32\svchost.exe[700] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00F00000
.text C:\WINDOWS\system32\svchost.exe[700] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00F00FE5
.text C:\WINDOWS\system32\svchost.exe[700] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00F0001B
.text C:\WINDOWS\system32\svchost.exe[700] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00F00FCA
.text C:\WINDOWS\system32\svchost.exe[700] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00ED0FEF
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F40FEF
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F40080
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F40F8B
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F40FA8
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F40FB9
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F40047
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F400B3
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F400A2
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F40104
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F400F3
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F40115
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F40FCA
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F4000A
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F40091
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F4002C
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F4001B
.text C:\WINDOWS\system32\svchost.exe[780] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F400CE
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F20011
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F20F79
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F20000
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F20FCA
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F20F94
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F20FE5
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F20FA5
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [12, 89]
.text C:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F20022
.text C:\WINDOWS\system32\svchost.exe[780] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F10053
.text C:\WINDOWS\system32\svchost.exe[780] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F10042
.text C:\WINDOWS\system32\svchost.exe[780] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F10027
.text C:\WINDOWS\system32\svchost.exe[780] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[780] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F10FD2
.text C:\WINDOWS\system32\svchost.exe[780] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F10FE3
.text C:\WINDOWS\system32\svchost.exe[780] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00F30FE5
.text C:\WINDOWS\system32\svchost.exe[780] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00F30FD4
.text C:\WINDOWS\system32\svchost.exe[780] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00F30FC3
.text C:\WINDOWS\system32\svchost.exe[780] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00F3000A
.text C:\WINDOWS\system32\svchost.exe[780] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0246000A
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 024600AC
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02460091
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02460FC3
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02460080
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02460FD4
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02460F81
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02460F92
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02460106
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 024600EB
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02460F5C
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02460065
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02460FEF
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 024600BD
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02460036
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02460025
.text C:\WINDOWS\System32\svchost.exe[844] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 024600DA
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 017F0FCD
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 017F0F97
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 017F001E
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 017F0FDE
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 017F0054
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 017F0FEF
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 017F002F
.text C:\WINDOWS\System32\svchost.exe[844] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 017F0FB2
.text C:\WINDOWS\System32\svchost.exe[844] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 017E004E
.text C:\WINDOWS\System32\svchost.exe[844] msvcrt.dll!system 77C293C7 5 Bytes JMP 017E0FC3
.text C:\WINDOWS\System32\svchost.exe[844] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 017E0FDE
.text C:\WINDOWS\System32\svchost.exe[844] msvcrt.dll!_open 77C2F566 5 Bytes JMP 017E0FEF
.text C:\WINDOWS\System32\svchost.exe[844] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 017E0033
.text C:\WINDOWS\System32\svchost.exe[844] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 017E000C
.text C:\WINDOWS\System32\svchost.exe[844] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01800000
.text C:\WINDOWS\System32\svchost.exe[844] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 01800011
.text C:\WINDOWS\System32\svchost.exe[844] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 01800022
.text C:\WINDOWS\System32\svchost.exe[844] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 01800FDB
.text C:\WINDOWS\System32\svchost.exe[844] WS2_32.dll!socket 71AB4211 5 Bytes JMP 017D0FEF
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00920FEF
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00920F44
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00920039
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00920028
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00920F6B
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00920F97
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00920F1F
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00920067
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009200A0
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00920EFD
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00920EEC
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00920F86
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00920FDE
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0092004A
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00920FBC
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00920FCD
.text C:\WINDOWS\system32\svchost.exe[904] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00920F0E
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00900039
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00900FA8
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00900FDE
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00900014
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0090005B
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00900FEF
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00900FB9
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [B0, 88] {MOV AL, 0x88}
.text C:\WINDOWS\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0090004A
.text C:\WINDOWS\system32\svchost.exe[904] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 008F0FB4
.text C:\WINDOWS\system32\svchost.exe[904] msvcrt.dll!system 77C293C7 5 Bytes JMP 008F003F
.text C:\WINDOWS\system32\svchost.exe[904] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 008F002E
.text C:\WINDOWS\system32\svchost.exe[904] msvcrt.dll!_open 77C2F566 5 Bytes JMP 008F0000
.text C:\WINDOWS\system32\svchost.exe[904] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 008F0FCF
.text C:\WINDOWS\system32\svchost.exe[904] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 008F001D
.text C:\WINDOWS\system32\svchost.exe[904] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00910FEF
.text C:\WINDOWS\system32\svchost.exe[904] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00910FD4
.text C:\WINDOWS\system32\svchost.exe[904] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00910FB9
.text C:\WINDOWS\system32\svchost.exe[904] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00910FA8
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A50FE5
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A50084
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A50073
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A50062
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A50051
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A50036
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A50F4D
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A50F74
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A500C1
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A50F28
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A50F0D
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A50FAF
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A5009F
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A50FCA
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A5001B
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A500B0
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A30FDE
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A30F90
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A30FEF
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A30025
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A30FA1
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A3000A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A30FBC