GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-07-02 19:32:00 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort1 ST9160310AS rev.0303 Running: s8gletsq.exe; Driver: C:\DOCUME~1\nowy\USTAWI~1\Temp\fwldqpow.sys ---- System - GMER 1.0.15 ---- SSDT sptd.sys ZwCreateKey [0xF72AEA50] SSDT sptd.sys ZwEnumerateKey [0xF72E2FFE] SSDT sptd.sys ZwEnumerateValueKey [0xF72E338C] SSDT sptd.sys ZwOpenKey [0xF72AEA30] SSDT sptd.sys ZwQueryKey [0xF72E3464] SSDT sptd.sys ZwQueryValueKey [0xF72E32E4] SSDT sptd.sys ZwSetValueKey [0xF72E34F6] INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D70D6 INT 0x06 \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) F5AD016D INT 0x0E \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) F5ACFFC2 INT 0x62 ? 8A670CC8 INT 0x63 ? 8A499CC8 INT 0x83 ? 8A670CC8 INT 0x94 ? 8A499CC8 INT 0xA4 ? 8A499CC8 Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateFile [0xF707023E] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcess [0xF7070090] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF70700A4] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF7070110] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF707013C] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwLoadKey2 [0xF70701C0] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF707027E] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF70701EC] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF7070054] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF7070068] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF7070252] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF707017E] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF7070126] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwReplaceKey [0xF7070214] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRestoreKey [0xF7070200] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetContextThread [0xF70700CE] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF70700BA] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF70702AD] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnloadKey [0xF70701D6] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF7070294] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF7070268] Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtCreateFile Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetInformationProcess ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2C80 80504538 4 Bytes JMP 91B0F72A .text ntkrnlpa.exe!ZwCallbackReturn + 2DB8 80504670 4 Bytes [30, EA, 2A, F7] {XOR DL, CH; SUB DH, BH} .sptd2 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd2" section [0xF736BD38] ? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text ACPI.sys F722C300 24 Bytes [00, 00, 00, 00, 00, 00, 8B, ...] .text ACPI.sys F722C319 7 Bytes [00, 6A, 0C, E8, AD, 13, 01] .text ACPI.sys F722C321 4 Bytes [56, 68, CA, F6] .text ACPI.sys F722C327 3 Bytes [68, 5B, 2A] .text ACPI.sys F722C339 7 Bytes [56, 6A, 0B, E8, 8D, 13, 01] .text ... .text C:\WINDOWS\system32\drivers\ACPI.sys section is writeable [0xF722C300, 0x1AF00, 0xE8000020] .rsrc C:\WINDOWS\system32\drivers\ACPI.sys section is executable [0xF7255F00, 0x1BF8, 0xE8000040] .reloc C:\WINDOWS\system32\drivers\ACPI.sys section is executable [0xF7257B00, 0x2506, 0xE8000040] .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6273000, 0x189F82, 0xE8000020] .text USBPORT.SYS!DllUnload F61F68AC 5 Bytes JMP 8A4991D8 .text agzx26m2.SYS F6039306 74 Bytes [00, 00, 00, 40, 03, 00, 40, ...] .text agzx26m2.SYS F6039351 87 Bytes [00, 00, 00, 00, 00, 00, 00, ...] .text agzx26m2.SYS F60393A9 10 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL} .text agzx26m2.SYS F60393B4 34 Bytes [40, 00, 00, C8, 50, 41, 47, ...] .text agzx26m2.SYS F60393D7 1 Byte [00] .text ... .text C:\WINDOWS\system32\drivers\aksfridge.sys section is writeable [0xA84FB000, 0x49379, 0xE0000020] .init C:\WINDOWS\system32\drivers\aksfridge.sys entry point in ".init" section [0xA8551224] .init C:\WINDOWS\system32\drivers\aksfridge.sys unknown last code section [0xA8551000, 0x4000, 0xE20000E0] .text C:\WINDOWS\system32\drivers\hardlock.sys section is writeable [0xA8312400, 0x6EB98, 0xE8000020] .protect˙˙˙˙hardlockentry point in ".protect˙˙˙˙hardlockentry point in ".protect˙˙˙˙hardlockentry point in ".p" section [0xA839CC20] C:\WINDOWS\system32\drivers\hardlock.sys entry point in ".protect˙˙˙˙hardlockentry point in ".protect˙˙˙˙hardlockentry point in ".p" section [0xA839CC20] .protect˙˙˙˙hardlockunknown last code section [0xA839CA00, 0x50CA, 0xE0000020] C:\WINDOWS\system32\drivers\hardlock.sys unknown last code section [0xA839CA00, 0x50CA, 0xE0000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00ED0000 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00ED0F52 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00ED0047 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00ED0F79 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00ED0036 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00ED0FA5 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00ED0F1A .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00ED0062 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00ED0EEE .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00ED0087 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00ED00AC .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00ED0F94 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00ED0011 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00ED0F37 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00ED0FCA .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00ED0FDB .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00ED0F09 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00EC0F94 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00EC0F3C .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00EC0FB9 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00EC0FD4 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00EC0F57 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00EC0FE5 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00EC0F72 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [0D, 89] .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00EC0F83 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00EB0FBE .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] msvcrt.dll!system 77C193C7 5 Bytes JMP 00EB0049 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00EB001D .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00EB0FEF .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00EB0038 .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00EB000C .text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[180] WS2_32.dll!socket 71A54211 5 Bytes JMP 00EA0FEF .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01160000 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01160F63 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01160062 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01160051 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01160036 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01160F9E .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01160F48 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01160090 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01160F1C .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011600B5 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01160F0B .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01160025 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01160FE5 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01160073 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01160FB9 .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01160FCA .text C:\WINDOWS\system32\services.exe[628] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01160F37 .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00FF0047 .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00FF00B3 .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00FF0036 .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00FF001B .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00FF0098 .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00FF0000 .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00FF007D .text C:\WINDOWS\system32\services.exe[628] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00FF006C .text C:\WINDOWS\system32\services.exe[628] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00FE004E .text C:\WINDOWS\system32\services.exe[628] msvcrt.dll!system 77C193C7 5 Bytes JMP 00FE003D .text C:\WINDOWS\system32\services.exe[628] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00FE0022 .text C:\WINDOWS\system32\services.exe[628] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00FE0000 .text C:\WINDOWS\system32\services.exe[628] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00FE0FC3 .text C:\WINDOWS\system32\services.exe[628] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00FE0011 .text C:\WINDOWS\system32\services.exe[628] WS2_32.dll!socket 71A54211 5 Bytes JMP 00FD0000 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C00FEF .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C0005D .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C0004C .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C00F72 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C00F8D .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C00FA8 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C00078 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C00F3C .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C00EF3 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C00F0E .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C00EE2 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C0002F .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C00FDE .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C00F4D .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C00FB9 .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C0000A .text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C00F1F .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00BF0036 .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00BF0062 .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00BF001B .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00BF000A .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00BF0047 .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00BF0FEF .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00BF0FAF .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [E0, 88] {LOOPNZ 0xffffffffffffff8a} .text C:\WINDOWS\system32\lsass.exe[640] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00BF0FC0 .text C:\WINDOWS\system32\lsass.exe[640] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00BE0FA6 .text C:\WINDOWS\system32\lsass.exe[640] msvcrt.dll!system 77C193C7 5 Bytes JMP 00BE0FB7 .text C:\WINDOWS\system32\lsass.exe[640] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00BE0FD2 .text C:\WINDOWS\system32\lsass.exe[640] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00BE000C .text C:\WINDOWS\system32\lsass.exe[640] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00BE0027 .text C:\WINDOWS\system32\lsass.exe[640] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00BE0FEF .text C:\WINDOWS\system32\lsass.exe[640] WS2_32.dll!socket 71A54211 5 Bytes JMP 00BD0FEF .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C00FE5 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtectEx 7C801A61 1 Byte [E9] .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C00065 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C0004A .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C00F72 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C00F83 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C00025 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C00F33 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C00F44 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C000CC .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C000A7 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C000DD .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C00F9E .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C00000 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C00F55 .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C00FAF .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C00FCA .text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C00096 .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00BF003D .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00BF0FC7 .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00BF002C .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00BF0011 .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00BF008E .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00BF0000 .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00BF0073 .text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00BF0058 .text C:\WINDOWS\system32\svchost.exe[828] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00BE0FC5 .text C:\WINDOWS\system32\svchost.exe[828] msvcrt.dll!system 77C193C7 5 Bytes JMP 00BE0050 .text C:\WINDOWS\system32\svchost.exe[828] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00BE002E .text C:\WINDOWS\system32\svchost.exe[828] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00BE000C .text C:\WINDOWS\system32\svchost.exe[828] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00BE003F .text C:\WINDOWS\system32\svchost.exe[828] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00BE001D .text C:\WINDOWS\system32\svchost.exe[828] WS2_32.dll!socket 71A54211 5 Bytes JMP 00BD0000 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D40000 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!VirtualProtectEx 7C801A61 1 Byte [E9] .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D40F65 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D40F80 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D40064 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D40047 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D40FAF .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D4008B .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D40F39 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D40F17 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D40F28 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D400CB .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D4002C .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D40FE5 .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D40F4A .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D40FCA .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D4001B .text C:\WINDOWS\system32\svchost.exe[896] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D400A6 .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00D30FC0 .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00D30047 .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00D3001B .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00D30000 .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00D30F8A .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00D30FE5 .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00D3002C .text C:\WINDOWS\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00D30FA5 .text C:\WINDOWS\system32\svchost.exe[896] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00D20FA6 .text C:\WINDOWS\system32\svchost.exe[896] msvcrt.dll!system 77C193C7 5 Bytes JMP 00D20027 .text C:\WINDOWS\system32\svchost.exe[896] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00D20FB7 .text C:\WINDOWS\system32\svchost.exe[896] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00D20FEF .text C:\WINDOWS\system32\svchost.exe[896] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00D2000C .text C:\WINDOWS\system32\svchost.exe[896] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00D20FD2 .text C:\WINDOWS\system32\svchost.exe[896] WS2_32.dll!socket 71A54211 5 Bytes JMP 00D10000 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02610000 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 026100C9 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02610FCA .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02610098 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0261007D .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02610051 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 026100DA .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02610F92 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02610F6D .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02610106 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02610121 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02610062 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0261001B .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02610FB9 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02610040 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02610FE5 .text C:\WINDOWS\System32\svchost.exe[988] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 026100F5 .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 0260002C .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 02600058 .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 0260001B .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 02600FE5 .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 02600FA5 .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 02600000 .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 02600047 .text C:\WINDOWS\System32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 02600FC0 .text C:\WINDOWS\System32\svchost.exe[988] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 025F0FB5 .text C:\WINDOWS\System32\svchost.exe[988] msvcrt.dll!system 77C193C7 5 Bytes JMP 025F0040 .text C:\WINDOWS\System32\svchost.exe[988] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 025F001B .text C:\WINDOWS\System32\svchost.exe[988] msvcrt.dll!_open 77C1F566 5 Bytes JMP 025F0FE3 .text C:\WINDOWS\System32\svchost.exe[988] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 025F0FC6 .text C:\WINDOWS\System32\svchost.exe[988] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 025F0000 .text C:\WINDOWS\System32\svchost.exe[988] WS2_32.dll!socket 71A54211 5 Bytes JMP 025E0FEF .text C:\WINDOWS\System32\svchost.exe[988] WININET.dll!InternetOpenA 3FD1D6A8 5 Bytes JMP 025C0FE5 .text C:\WINDOWS\System32\svchost.exe[988] WININET.dll!InternetOpenW 3FD1DB21 5 Bytes JMP 025C0FD4 .text C:\WINDOWS\System32\svchost.exe[988] WININET.dll!InternetOpenUrlA 3FD1F3BC 5 Bytes JMP 025C000A .text C:\WINDOWS\System32\svchost.exe[988] WININET.dll!InternetOpenUrlW 3FD66DFF 5 Bytes JMP 025C0FB9 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 006A0000 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 006A0F55 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 006A0F70 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 006A0054 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 006A0F97 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 006A002F .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 006A0F38 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 006A0080 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006A00D1 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 006A00AC .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006A00E2 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 006A0FA8 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 006A0FEF .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 006A006F .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 006A0FC3 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 006A0FD4 .text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 006A009B .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00690051 .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00690FB9 .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00690036 .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 0069001B .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00690FCA .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 0069000A .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00690062 .text C:\WINDOWS\system32\svchost.exe[1036] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00690FDB .text C:\WINDOWS\system32\svchost.exe[1036] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 0068003B .text C:\WINDOWS\system32\svchost.exe[1036] msvcrt.dll!system 77C193C7 5 Bytes JMP 00680FB0 .text C:\WINDOWS\system32\svchost.exe[1036] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 0068000C .text C:\WINDOWS\system32\svchost.exe[1036] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00680FEF .text C:\WINDOWS\system32\svchost.exe[1036] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00680FC1 .text C:\WINDOWS\system32\svchost.exe[1036] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00680FD2 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C00FE5 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C00F70 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C00065 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C00054 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C00FA1 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C00039 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C00F1D .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C00F2E .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C0008A .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C00EFB .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C00ED6 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C00FB2 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C00FD4 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C00F4B .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C00014 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C00FC3 .text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C00F0C .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00BF001E .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00BF0040 .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00BF0FCD .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00BF0FDE .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00BF0F83 .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00BF0FEF .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00BF002F .text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00BF0FB2 .text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00BE007A .text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!system 77C193C7 5 Bytes JMP 00BE0069 .text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00BE0FEF .text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00BE000C .text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00BE004E .text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00BE001D .text C:\WINDOWS\system32\svchost.exe[1256] WS2_32.dll!socket 71A54211 5 Bytes JMP 00BD0FEF .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CF0000 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CF0F7E .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CF0F99 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CF0FAA .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CF0073 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CF0047 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CF00BC .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CF009F .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CF0F4F .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CF00E8 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CF00F9 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CF0058 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CF0FE5 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CF008E .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CF0036 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CF0025 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CF00D7 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00CE0FCA .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00CE0F97 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00CE001B .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00CE000A .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00CE004A .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00CE0FEF .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00CE0FA8 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [EF, 88] .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00CE0FB9 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00CD0FBE .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] msvcrt.dll!system 77C193C7 5 Bytes JMP 00CD0049 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00CD0027 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00CD000C .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00CD0038 .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00CD0FEF .text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[1704] WS2_32.dll!socket 71A54211 5 Bytes JMP 00CC000A .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 5CE60FEF .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 5CE60F5F .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 5CE60F70 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!LoadLibraryExW 7C801AF5 4 Bytes JMP 5CE6004A .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 5CE6002F .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 5CE60F8D .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 5CE6006F .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 5CE60F27 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 5CE600A5 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 5CE60F16 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 5CE600B6 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 5CE6001E .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 5CE60FD4 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 5CE60F44 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 5CE60F9E .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 5CE60FC3 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 5CE60094 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 5CE40FB7 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] msvcrt.dll!system 77C193C7 5 Bytes JMP 5CE40FC8 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 5CE40027 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] msvcrt.dll!_open 77C1F566 5 Bytes JMP 5CE40FEF .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 5CE40038 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 5CE4000C .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 5CE5001B .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 5CE50F97 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 5CE5000A .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 5CE50FD4 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 5CE50FA8 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 5CE50FEF .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 5CE50FB9 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [06, E5] .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 5CE50036 .text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1824] WS2_32.dll!socket 71A54211 5 Bytes JMP 5CE30000 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E80FEF .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E80F77 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E80076 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E8005B .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E8004A .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E80FAF .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E8009D .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E80F55 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E800D3 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E80F3A .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E800EE .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E80F9E .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E80000 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E80F66 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E80FC0 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E80011 .text C:\WINDOWS\Explorer.EXE[1880] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E800AE .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00E7002F .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00E70091 .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00E70014 .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00E70FDE .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00E70076 .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00E70FEF .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00E7005B .text C:\WINDOWS\Explorer.EXE[1880] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00E70040 .text C:\WINDOWS\Explorer.EXE[1880] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00E60FD2 .text C:\WINDOWS\Explorer.EXE[1880] msvcrt.dll!system 77C193C7 5 Bytes JMP 00E60FE3 .text C:\WINDOWS\Explorer.EXE[1880] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00E6002E .text C:\WINDOWS\Explorer.EXE[1880] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00E60000 .text C:\WINDOWS\Explorer.EXE[1880] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00E60053 .text C:\WINDOWS\Explorer.EXE[1880] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00E6001D .text C:\WINDOWS\Explorer.EXE[1880] WININET.dll!InternetOpenA 3FD1D6A8 5 Bytes JMP 00CC0000 .text C:\WINDOWS\Explorer.EXE[1880] WININET.dll!InternetOpenW 3FD1DB21 5 Bytes JMP 00CC0FE5 .text C:\WINDOWS\Explorer.EXE[1880] WININET.dll!InternetOpenUrlA 3FD1F3BC 5 Bytes JMP 00CC0FD4 .text C:\WINDOWS\Explorer.EXE[1880] WININET.dll!InternetOpenUrlW 3FD66DFF 5 Bytes JMP 00CC0FC3 .text C:\WINDOWS\Explorer.EXE[1880] WS2_32.dll!socket 71A54211 5 Bytes JMP 00D90FEF .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F5000A .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F50F88 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F50F99 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F50FB6 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F50073 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F50FDB .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F500C4 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F500B3 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F50F2B .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F50F46 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F50F10 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F50062 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F50025 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F50098 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F50047 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F50036 .text C:\WINDOWS\system32\svchost.exe[2160] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F50F57 .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00F40FAF .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00F40051 .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00F40000 .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00F40FD4 .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00F40036 .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00F40FEF .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00F40F94 .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [15, 89] .text C:\WINDOWS\system32\svchost.exe[2160] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00F4001B .text C:\WINDOWS\system32\svchost.exe[2160] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00F30F7A .text C:\WINDOWS\system32\svchost.exe[2160] msvcrt.dll!system 77C193C7 5 Bytes JMP 00F30F95 .text C:\WINDOWS\system32\svchost.exe[2160] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00F30FC1 .text C:\WINDOWS\system32\svchost.exe[2160] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00F30FE3 .text C:\WINDOWS\system32\svchost.exe[2160] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00F30FA6 .text C:\WINDOWS\system32\svchost.exe[2160] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00F30FD2 .text C:\WINDOWS\system32\svchost.exe[2160] WS2_32.dll!socket 71A54211 5 Bytes JMP 00F20FEF .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B10000 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B1007F .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B10F94 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B10062 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B10051 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B10FC0 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B100B5 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B10F79 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B100E4 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B10F41 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B100F5 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B10FAF .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B10011 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B100A4 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B10FD1 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B10022 .text C:\WINDOWS\system32\wuauclt.exe[3376] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B10F52 .text C:\WINDOWS\system32\wuauclt.exe[3376] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00AF0064 .text C:\WINDOWS\system32\wuauclt.exe[3376] msvcrt.dll!system 77C193C7 5 Bytes JMP 00AF0053 .text C:\WINDOWS\system32\wuauclt.exe[3376] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00AF0038 .text C:\WINDOWS\system32\wuauclt.exe[3376] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00AF000C .text C:\WINDOWS\system32\wuauclt.exe[3376] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00AF0FE3 .text C:\WINDOWS\system32\wuauclt.exe[3376] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00AF001D .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00B00FB9 .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00B00F4D .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00B00FD4 .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00B0000A .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00B00F72 .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00B00FEF .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00B00F8D .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [D1, 88] .text C:\WINDOWS\system32\wuauclt.exe[3376] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00B00F9E .text C:\WINDOWS\system32\wuauclt.exe[3376] ws2_32.dll!socket 71A54211 5 Bytes JMP 00AE0FE5 .text C:\Program Files\Mozilla Firefox\firefox.exe[5756] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 011AFA35 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[5756] kernel32.dll!VirtualAlloc 7C809AF1 5 Bytes JMP 014507C5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[5756] kernel32.dll!MapViewOfFile 7C80B9A5 5 Bytes JMP 0145079E C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[5756] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 013329CB C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[5756] GDI32.dll!CreateDIBSection 77F19E19 5 Bytes JMP 01450728 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5800] USER32.dll!SetWindowLongA 7E37C29D 5 Bytes JMP 1066003B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5800] USER32.dll!SetWindowLongW 7E37C2BB 5 Bytes JMP 1065FFCA C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5800] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1043AEF3 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5800] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 1043B50D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_ULONG] [F7275574] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!READ_PORT_UCHAR] [F72750C0] sptd.sys IAT \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_UCHAR] [F7275FE0] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F72750C0] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F7275362] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F72752A4] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F72761BC] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F7275FE0] sptd.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F728A312] sptd.sys IAT \SystemRoot\System32\Drivers\agzx26m2.SYS[HAL.dll!KeGetCurrentIrql] 830C4D8A IAT \SystemRoot\System32\Drivers\agzx26m2.SYS[HAL.dll!KfAcquireSpinLock] 0001CCB8 IAT \SystemRoot\System32\Drivers\agzx26m2.SYS[HAL.dll!KfReleaseSpinLock] 48880000 IAT \SystemRoot\System32\Drivers\agzx26m2.SYS[HAL.dll!KfRaiseIrql] C0940F68 IAT \SystemRoot\System32\Drivers\agzx26m2.SYS[HAL.dll!KfLowerIrql] 8B55C35D IAT \SystemRoot\System32\Drivers\agzx26m2.SYS[USBD.SYS!USBD_CreateConfigurationRequestEx] 458D5653 ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINDOWS\system32\mfevtps.exe[1680] @ C:\WINDOWS\system32\CRYPT32.dll [ADVAPI32.dll!RegQueryValueExW] [00405941] C:\WINDOWS\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8A66F1F8 AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.) Device \FileSystem\Fastfat \FatCdrom 893911F8 AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) Device \Driver\usbohci \Device\USBPDO-0 8A37A1F8 Device \Driver\usbohci \Device\USBPDO-1 8A37A1F8 Device \Driver\usbehci \Device\USBPDO-2 8A48D1F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{A2C7841E-D57D-4811-A1B9-02CA097E8C88} 89D121F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{B7996051-B631-4887-A671-4E259F86CA74} 89D121F8 AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.) Device \Driver\Cdrom \Device\CdRom0 8A385430 Device \Driver\atapi \Device\Ide\IdePort0 [F71C7B40] atapi.sys[unknown section] {INT 3 ; PUSH ESP; AND AL, 0x8; LEA ECX, [ESP+0x4]; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F71C7B40] atapi.sys[unknown section] {INT 3 ; PUSH ESP; AND AL, 0x8; LEA ECX, [ESP+0x4]; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F71C7B40] atapi.sys[unknown section] {INT 3 ; PUSH ESP; AND AL, 0x8; LEA ECX, [ESP+0x4]; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F71C7B40] atapi.sys[unknown section] {INT 3 ; PUSH ESP; AND AL, 0x8; LEA ECX, [ESP+0x4]; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F71C7B40] atapi.sys[unknown section] {INT 3 ; PUSH ESP; AND AL, 0x8; LEA ECX, [ESP+0x4]; PUSH EAX} Device \Driver\usbstor \Device\000000a7 894011F8 Device \Driver\usbstor \Device\000000a8 894011F8 Device \Driver\PCI_PNP4984 \Device\00000069 sptd.sys Device \Driver\NetBT \Device\NetBt_Wins_Export 89D121F8 Device \Driver\NetBT \Device\NetbiosSmb 89D121F8 AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.) Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.) AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.) Device \Driver\Disk \Device\Harddisk1\DR7 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.) Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+8 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.) Device \Driver\Disk \Device\Harddisk2\DR4 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.) Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+6 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.) Device \Driver\usbohci \Device\USBFDO-0 8A37A1F8 Device \Driver\usbohci \Device\USBFDO-1 8A37A1F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 894101F8 Device \Driver\usbehci \Device\USBFDO-2 8A48D1F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 894101F8 Device \Driver\agzx26m2 \Device\Scsi\agzx26m21 8A3421F8 Device \FileSystem\Fastfat \Fat 893911F8 AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.) Device \FileSystem\Cdfs \Cdfs 8A3E91F8 ---- Threads - GMER 1.0.15 ---- Thread System [4:144] 8A53139F Thread System [4:148] 8A42E0F4 ---- Processes - GMER 1.0.15 ---- Library c:\windows\system32\n (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [988] 0x45670000 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0x3F 0x4A 0x84 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0x3F 0x4A 0x84 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... ---- EOF - GMER 1.0.15 ----