Hier der Gmer-Log Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-02-27 15:55:15
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1200BEVS-22UST0 rev.01.01A01
Running: 9ovzew1d.exe; Driver: C:\DOKUME~1\curry36\LOKALE~1\Temp\agddiuob.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xAA0F6444]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xAA0F5C8A]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xAA0F5958]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xF7661A20]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xAA0F7520]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xAA0F5A68]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xAA0F5B5A]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xF76622A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xF766D910]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xAA0F6780]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xAA0F5F9C]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwOpenKey [0xF766D794]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xF76622C8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryValueKey [0xF766D866]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0xAA0F60D2]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xF766D0B0]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xAA0F577E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xAA0F66C8]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xAA0F62BC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xAA00195A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xAA00196E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xAA0019EE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xAA001B1F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xAA001932]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xAA001946]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xAA0019C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xAA001ACA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xAA001A72]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xAA001B47]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xAA001B33]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xAA001998]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xAA001984]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xAA001B09]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xAA001A04]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xAA0019D8]
Code \??\C:\DOKUME~1\curry36\LOKALE~1\Temp\catchme.sys pIofCallDriver
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution 80515AB2 7 Bytes JMP AA0019DC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 80574B1F 5 Bytes JMP AA001988 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057A7A9 5 Bytes JMP AA001A08 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057AC21 7 Bytes JMP AA0019F2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 8057F56B 7 Bytes JMP AA0019C6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 8057F93A 5 Bytes JMP AA001936 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8058B9EC 7 Bytes JMP AA001972 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 80596743 5 Bytes JMP AA00194A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 80596D8A 5 Bytes JMP AA001B23 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805C7A4D 5 Bytes JMP AA00195E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 80635EFB 5 Bytes JMP AA00199C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 80655A96 7 Bytes JMP AA001B0D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 806563CF 7 Bytes JMP AA001ACE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8065684C 7 Bytes JMP AA001A76 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 80656D3D 5 Bytes JMP AA001B37 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 806571A8 5 Bytes JMP AA001B4B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. !
? C:\DOKUME~1\curry36\LOKALE~1\Temp\catchme.sys Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0000
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF008B
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF007A
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0069
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0058
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF003D
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF00B7
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF00A6
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF0F32
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF0F43
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF00DC
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0FC0
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF0FDB
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF0F7B
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF002C
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0011
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF0F54
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00BE0F9E
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00BE0F57
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00BE0FC3
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00BE0FD4
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00BE0F68
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00BE0014
.text C:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00BE0F8D
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00BD0FA6
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00BD0FB7
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00BD0FD2
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00BD0000
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00BD0027
.text C:\WINDOWS\system32\svchost.exe[440] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FE5
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00070056
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00070045
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070F6B
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00070F7C
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00070F97
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00070F29
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00070071
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00070F0E
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 000700A7
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00070EF3
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00070028
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00070F46
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00070FB2
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00070FC3
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0007008C
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00060FCA
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00060073
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00060FDB
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 0006001B
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00060058
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 0006000A
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00060047
.text C:\WINDOWS\system32\services.exe[824] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00060036
.text C:\WINDOWS\system32\services.exe[824] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00050F7F
.text C:\WINDOWS\system32\services.exe[824] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00050F90
.text C:\WINDOWS\system32\services.exe[824] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[824] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[824] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00050FAB
.text C:\WINDOWS\system32\services.exe[824] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00050FC6
.text C:\WINDOWS\system32\services.exe[824] WS2_32.dll!socket 71A14211 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F90000
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F9009A
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F9007F
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F90062
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F90051
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F90FC0
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F900BF
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F90F6D
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F90F26
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F90F41
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F900E4
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F90FAF
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F90FE5
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F90F8A
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F9002C
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F9001B
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F90F5C
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00F80040
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00F80080
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00F80025
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00F80FE5
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00F80FB9
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00F80000
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00F80065
.text C:\WINDOWS\system32\lsass.exe[836] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00F80FD4
.text C:\WINDOWS\system32\lsass.exe[836] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00F7002E
.text C:\WINDOWS\system32\lsass.exe[836] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00F7001D
.text C:\WINDOWS\system32\lsass.exe[836] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00F70FC8
.text C:\WINDOWS\system32\lsass.exe[836] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00F70000
.text C:\WINDOWS\system32\lsass.exe[836] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00F70FAD
.text C:\WINDOWS\system32\lsass.exe[836] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00F70FE3
.text C:\WINDOWS\system32\lsass.exe[836] WS2_32.dll!socket 71A14211 5 Bytes JMP 00F60FEF
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80000
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F80F7C
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80071
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80F8D
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80FA8
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F80040
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80F57
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F8009D
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F800F0
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F800DF
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F80101
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F80FB9
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80FE5
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F8008C
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F80FD4
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F8001B
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F800C4
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00F70FCD
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00F70065
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00F70014
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00F70FDE
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00F70FA8
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00F70FEF
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00F70054
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00F70039
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00F6003A
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00F60029
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00F60FD4
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00F60FEF
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00F60FC3
.text C:\WINDOWS\system32\svchost.exe[984] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00F6000C
.text C:\WINDOWS\system32\svchost.exe[984] WS2_32.dll!socket 71A14211 5 Bytes JMP 00F50FEF
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CA0000
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CA0F48
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CA0F59
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CA003D
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CA0F80
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CA0FB6
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CA007F
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CA0F37
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CA00D0
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CA00BF
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CA0F1C
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CA0F91
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CA0011
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CA0058
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CA0FD1
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CA0022
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CA00A4
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00C9001B
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00C90F72
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00C90FD4
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00C9000A
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00C90F8D
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00C90FEF
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00C90F9E
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [EC, 88]
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00C90FAF
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00C80040
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00C80FB5
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00C80FC6
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!_open 77BFF566 3 Bytes JMP 00C80FE3
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!_open + 4 77BFF56A 1 Byte [89]
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00C8001B
.text C:\WINDOWS\system32\svchost.exe[1068] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00C80000
.text C:\WINDOWS\system32\svchost.exe[1068] WS2_32.dll!socket 71A14211 5 Bytes JMP 00C70000
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02020000
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0202007F
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02020064
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02020053
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02020F8A
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02020FA5
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02020F59
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 020200A1
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 020200E8
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 020200CD
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02020103
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0202002C
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02020FE5
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02020090
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0202001B
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02020FCA
.text C:\WINDOWS\System32\svchost.exe[1120] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 020200BC
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 02010025
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 02010F8D
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 02010FD4
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 02010014
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 02010F9E
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 02010FEF
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 0201004A
.text C:\WINDOWS\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 02010FB9
.text C:\WINDOWS\System32\svchost.exe[1120] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 01EC0F9C
.text C:\WINDOWS\System32\svchost.exe[1120] msvcrt.dll!system 77BF93C7 5 Bytes JMP 01EC0031
.text C:\WINDOWS\System32\svchost.exe[1120] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 01EC000C
.text C:\WINDOWS\System32\svchost.exe[1120] msvcrt.dll!_open 77BFF566 5 Bytes JMP 01EC0FE3
.text C:\WINDOWS\System32\svchost.exe[1120] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 01EC0FB7
.text C:\WINDOWS\System32\svchost.exe[1120] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 01EC0FD2
.text C:\WINDOWS\System32\svchost.exe[1120] WS2_32.dll!socket 71A14211 5 Bytes JMP 01A70FEF
.text C:\WINDOWS\System32\svchost.exe[1120] WININET.dll!InternetOpenW 7718AF61 5 Bytes JMP 01A90000
.text C:\WINDOWS\System32\svchost.exe[1120] WININET.dll!InternetOpenA 771957AE 5 Bytes JMP 01A90FEF
.text C:\WINDOWS\System32\svchost.exe[1120] WININET.dll!InternetOpenUrlA 77195A7A 5 Bytes JMP 01A90011
.text C:\WINDOWS\System32\svchost.exe[1120] WININET.dll!InternetOpenUrlW 771A5BB2 5 Bytes JMP 01A9002E
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00810FEF
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00810F3C
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00810F57
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00810F68
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00810F79
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00810FA5
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00810F15
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00810067
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00810EFA
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00810093
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00810EDF
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00810F8A
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00810000
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0081004C
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00810FC0
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00810011
.text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00810078
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00800036
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00800073
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00800025
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00800062
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00800051
.text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00800FCA
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 007F0FB2
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!system 77BF93C7 5 Bytes JMP 007F0FC3
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 007F0033
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_open 77BFF566 5 Bytes JMP 007F0000
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 007F0FDE
.text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 007F0FEF
.text C:\WINDOWS\system32\svchost.exe[1224] WS2_32.dll!socket 71A14211 5 Bytes JMP 007E0FEF
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B20FEF
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B20067
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B2004C
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B20F72
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B20F83
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B20FAF
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B20F46
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B20082
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B20F06
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B2009F
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B20EEB
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B20F9E
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B2000A
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B20F57
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B20025
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B20FD4
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B20F21
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00B10FCA
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00B10F94
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00B10FE5
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00B1001B
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00B10051
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00B10000
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00B10040
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00B10FB9
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00B00F9A
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00B00FAB
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00B0001B
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00B00000
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00B00FC6
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00B00FE3
.text C:\WINDOWS\system32\svchost.exe[1280] WS2_32.dll!socket 71A14211 5 Bytes JMP 006C000A
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00AA0FE5
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00AA0F52
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00AA0F63
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00AA0F7E
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00AA0047
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00AA0FAF
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00AA0090
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00AA007F
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00AA0F01
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00AA0F12
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00AA00B5
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00AA0036
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00AA000A
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00AA0062
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00AA001B
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00AA0FCA
.text C:\WINDOWS\system32\svchost.exe[1576] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00AA0F2D
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 3 Bytes JMP 00660025
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyExW + 4 77DA6AB3 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyExW 77DA776C 3 Bytes JMP 00660F97
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyExW + 4 77DA7770 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyExA 77DA7852 3 Bytes JMP 00660014
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyExA + 4 77DA7856 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyW 77DA7946 3 Bytes JMP 00660FD4
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyW + 4 77DA794A 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 3 Bytes JMP 00660054
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyExA + 4 77DAE9F8 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 3 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegOpenKeyA + 4 77DAEFCC 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00660FB2
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [89, 88]
.text C:\WINDOWS\system32\svchost.exe[1576] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00660FC3
.text C:\WINDOWS\system32\svchost.exe[1576] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00650FCA
.text C:\WINDOWS\system32\svchost.exe[1576] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00650055
.text C:\WINDOWS\system32\svchost.exe[1576] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00650029
.text C:\WINDOWS\system32\svchost.exe[1576] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1576] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00650044
.text C:\WINDOWS\system32\svchost.exe[1576] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00650FEF
.text C:\WINDOWS\system32\svchost.exe[1576] WININET.dll!InternetOpenW 7718AF61 5 Bytes JMP 00640025
.text C:\WINDOWS\system32\svchost.exe[1576] WININET.dll!InternetOpenA 771957AE 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\svchost.exe[1576] WININET.dll!InternetOpenUrlA 77195A7A 5 Bytes JMP 00640036
.text C:\WINDOWS\system32\svchost.exe[1576] WININET.dll!InternetOpenUrlW 771A5BB2 5 Bytes JMP 00640FD9
.text C:\WINDOWS\system32\svchost.exe[1576] WS2_32.dll!socket 71A14211 5 Bytes JMP 0063000A
.text c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe[1912] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe[1912] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0FE5
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0F30
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0F4B
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0025
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0F72
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0F9E
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0060
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F0E
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0ED1
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0EEC
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001A0085
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001A0F83
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001A0000
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001A0F1F
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001A0FAF
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001A0FCA
.text C:\WINDOWS\explorer.exe[1968] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001A0EFD
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00290FC0
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00290051
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00290011
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00290000
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00290F94
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00290FE5
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00290FA5
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [4C, 88]
.text C:\WINDOWS\explorer.exe[1968] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00290036
.text C:\WINDOWS\explorer.exe[1968] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 002A002C
.text C:\WINDOWS\explorer.exe[1968] msvcrt.dll!system 77BF93C7 5 Bytes JMP 002A0FA1
.text C:\WINDOWS\explorer.exe[1968] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 002A0FC6
.text C:\WINDOWS\explorer.exe[1968] msvcrt.dll!_open 77BFF566 5 Bytes JMP 002A0FE3
.text C:\WINDOWS\explorer.exe[1968] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 002A001B
.text C:\WINDOWS\explorer.exe[1968] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 002A0000
.text C:\WINDOWS\explorer.exe[1968] WININET.dll!InternetOpenW 7718AF61 5 Bytes JMP 002C0FEF
.text C:\WINDOWS\explorer.exe[1968] WININET.dll!InternetOpenA 771957AE 5 Bytes JMP 002C0000
.text C:\WINDOWS\explorer.exe[1968] WININET.dll!InternetOpenUrlA 77195A7A 5 Bytes JMP 002C001B
.text C:\WINDOWS\explorer.exe[1968] WININET.dll!InternetOpenUrlW 771A5BB2 5 Bytes JMP 002C0038
.text C:\WINDOWS\explorer.exe[1968] WS2_32.dll!socket 71A14211 5 Bytes JMP 017C0FEF
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortInitialize] 8639D940
IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortNotification] 8639D950
IAT aha154x.sys[SCSIPORT.SYS!ScsiPortNotification] 8639D588
IAT aha154x.sys[SCSIPORT.SYS!ScsiPortInitialize] 8639D578
IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortNotification] 863D4A08
IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D49F8
IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortNotification] 863D4640
IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D4630
IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortNotification] 8639C018
IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortInitialize] 8639C008
IAT amsint.sys[SCSIPORT.SYS!ScsiPortNotification] 8639CD50
IAT amsint.sys[SCSIPORT.SYS!ScsiPortInitialize] 8639CD40
IAT i2omp.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D3CC0
IAT i2omp.sys[SCSIPORT.SYS!ScsiPortNotification] 863D3CD0
IAT ini910u.sys[SCSIPORT.SYS!ScsiPortNotification] 863D3908
IAT ini910u.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D38F8
IAT ql1240.sys[SCSIPORT.SYS!ScsiPortNotification] 863D3540
IAT ql1240.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D3530
IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortNotification] 863D3178
IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D3168
IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortNotification] 8639B1F8
IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortInitialize] 8639B1E8
IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortNotification] 863D2018
IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D2008
IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortNotification] 863D2C50
IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D2C40
IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortNotification] 863D24C0
IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D24B0
IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortNotification] 8639A018
IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortInitialize] 8639A008
IAT perc2.sys[SCSIPORT.SYS!ScsiPortNotification] 863D1018
IAT perc2.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D1008
IAT hpn.sys[SCSIPORT.SYS!ScsiPortNotification] 863D1D50
IAT hpn.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D1D40
IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortNotification] 863D1988
IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortInitialize] 863D1978
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8632C030
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
Device \FileSystem\Fastfat \FatCdrom 8535D9A0
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\Cdrom \Device\CdRom0 8616D9E0
Device \FileSystem\Rdbss \Device\FsWrap 853683C8
Device \Driver\Cdrom \Device\CdRom2 8616D9E0
Device \Driver\USBSTOR \Device\000000c0 83C5E1C8
Device \Driver\USBSTOR \Device\000000c1 83C5E1C8
Device \Driver\USBSTOR \Device\000000c2 83C5E1C8
Device \FileSystem\Srv \Device\LanmanServer 85B43300
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\USBSTOR \Device\000000ac 83C5E1C8
Device \Driver\USBSTOR \Device\000000ad 83C5E1C8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 85362258
Device \FileSystem\MRxSmb \Device\LanmanRedirector 85362258
Device \FileSystem\Npfs \Device\NamedPipe 853B6E90
Device \FileSystem\Msfs \Device\Mailslot 8636D298
Device \Driver\d347prt \Device\Scsi\d347prt1Port2Path0Target0Lun0 8616DAE8
Device \Driver\d347prt \Device\Scsi\d347prt1 8616DAE8
Device \FileSystem\Fastfat \Fat 8535D9A0
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 863442F0
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 863442F0
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 863442F0
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 863442F0
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 863442F0
Device \FileSystem\Cdfs \Cdfs 85319A98
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z0 0x3A 0x25 0xAE 0xEE ...
---- EOF - GMER 1.0.15 ---- das mit OSAM hat nicht funktioniert, wenn ich die osam.exe ausführe zeigt mir winrar zwei Fehlermeldungen an und "osam.exe konnte nicht gefunden werden, weil ToolkitPro1211vc80U.dll nicht gefunden wurde. Was ist das?
MfG |