![]() |
Virus Anti Malware Doktor, wie überprüfe ich die vollständige Löschung? hallo Marvin_1980 ich hab genau das selbe problem gehabt wie du dann hab ich auch das programm Malwarebytes' Anti-Malware installiert bei mir ist der virus weg so wie es aussieht zumindest seh ich nichts mehr in der leiste aber irgend wie kann ich mein internet explorer nicht mehr öffnen, wenn ich es öffne ist da einfach nur ein weißer leerer bildschirm ich kann nur noch über firefox ins internet kann mir bitte bitte jemand weiter helfen??? |
:hallo: Eine Bereinigung ist mitunter mit viel Arbeit für Dich verbunden.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der Schnellere und immer der sicherste Weg. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass Du clean bist. Vista und Win7 User Alle Tools mit Rechtsklick "als Administrator ausführen" starten. Schritt 1 CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: netsvcs
Bitte poste in Deiner nächsten Antwort OTL.txt Extras.txt |
OTL Logfile: Code: OTL logfile created on: 15.06.2010 18:34:38 - Run 1 |
OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 15.06.2010 18:41:59 - Run 1 |
Schritt 1 Software mit Revo Uninstaller deinstallieren Downloade Dir bitte den Revo Uninstaller
Bebilderte Anleitung Schritt 2 Bereinigung mit Malwarebytes' Anti-Malware (Quick-Scan) Downloade Dir bitte Malwarebytes
Schritt 3
Code: :OTL
Schritt 4 CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: /md5start
Bitte poste in Deiner nächsten Antwort Log von MBAM Log von OTLFix OTL.txt |
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4201 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18928 15.06.2010 22:35:26 mbam-log-2010-06-15 (22-35-26).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 132744 Laufzeit: 4 Minute(n), 54 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Users\Bilal\AppData\Local\Temp\scmroewnxa.exe (Rootkit.Dropper) -> Quarantined and deleted successfully. |
All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. File C:\Programme\DVDVideoSoftTB\tbDVDV.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. File C:\Programme\DVDVideoSoftTB\tbDVDV.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bc04b34e-5dd8-465a-a5e0-86f7c11bc009} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc04b34e-5dd8-465a-a5e0-86f7c11bc009}\ not found. File C:\Programme\Games_Bar_1\tbGame.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\ not found. File C:\Programme\Search Settings\SearchSettings.dll not found. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin folder moved successfully. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\META-INF folder moved successfully. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\lib folder moved successfully. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\defaults folder moved successfully. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components folder moved successfully. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\chrome folder moved successfully. C:\Users\Bilal\AppData\Roaming\mozilla\Firefox\Profiles\llkfgiu3.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\ not found. File C:\Programme\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. File C:\Programme\DVDVideoSoftTB\tbDVDV.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc04b34e-5dd8-465a-a5e0-86f7c11bc009}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc04b34e-5dd8-465a-a5e0-86f7c11bc009}\ not found. File C:\Programme\Games_Bar_1\tbGame.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\ not found. File C:\Programme\Search Settings\SearchSettings.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\ not found. File C:\Programme\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. File C:\Programme\DVDVideoSoftTB\tbDVDV.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{bc04b34e-5dd8-465a-a5e0-86f7c11bc009} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc04b34e-5dd8-465a-a5e0-86f7c11bc009}\ not found. File C:\Programme\Games_Bar_1\tbGame.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}\ not found. File C:\Programme\DVDVideoSoftTB\tbDVDV.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BC04B34E-5DD8-465A-A5E0-86F7C11BC009} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC04B34E-5DD8-465A-A5E0-86F7C11BC009}\ not found. File C:\Programme\Games_Bar_1\tbGame.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings not found. File C:\Programme\Search Settings\SearchSettings.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d5734ef6-010d-11de-9963-0015af5855f8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d5734ef6-010d-11de-9963-0015af5855f8}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d5734ef6-010d-11de-9963-0015af5855f8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d5734ef6-010d-11de-9963-0015af5855f8}\ not found. File K:\LaunchU3.exe not found. C:\Users\Bilal\AppData\Roaming\lowsec folder moved successfully. C:\Users\Bilal\AppData\Roaming\E0B048B4C0008FA5EA948BBAC4FB6C03 folder moved successfully. Folder C:\Programme\Search Settings\ not found. Folder C:\Programme\Dealio Toolbar\ not found. Folder C:\Programme\DVDVideoSoftTB\ not found. C:\Users\Bilal\Documents\DVDVideoSoft\Temp folder moved successfully. C:\Users\Bilal\Documents\DVDVideoSoft\FreeYouTubeToMP3Converter folder moved successfully. C:\Users\Bilal\Documents\DVDVideoSoft folder moved successfully. C:\Programme\DVDVideoSoft\Free YouTube to MP3 Converter folder moved successfully. C:\Programme\DVDVideoSoft\Free Audio CD Burner folder moved successfully. Folder move failed. C:\Programme\DVDVideoSoft scheduled to be moved on reboot. C:\Programme\Common Files\DVDVideoSoft\TB folder moved successfully. C:\Programme\Common Files\DVDVideoSoft\Dll folder moved successfully. C:\Programme\Common Files\DVDVideoSoft folder moved successfully. C:\Programme\Conduit\Community Alerts folder moved successfully. Folder move failed. C:\Programme\Conduit scheduled to be moved on reboot. Folder C:\Programme\Games_Bar_1\ not found. ========== SERVICES/DRIVERS ========== ========== FILES ========== ========== REGISTRY ========== HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\"ProxyEnable"|Dword:00000000 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\"ProxyServer"|"" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Bilal ->Temp folder emptied: 3815203 bytes ->Temporary Internet Files folder emptied: 1156312036 bytes ->Java cache emptied: 1575232 bytes ->FireFox cache emptied: 50748829 bytes ->Google Chrome cache emptied: 7309217 bytes ->Flash cache emptied: 1050 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3223368 bytes RecycleBin emptied: 1384 bytes Total Files Cleaned = 1.166,00 mb OTL by OldTimer - Version 3.2.6.0 log created on 06152010_224043 Files\Folders moved on Reboot... Folder move failed. C:\Programme\DVDVideoSoft scheduled to be moved on reboot. Folder move failed. C:\Programme\Conduit scheduled to be moved on reboot. File\Folder C:\Windows\temp\JET648C.tmp not found! Registry entries deleted on Reboot... |
OTL Logfile: Code: OTL logfile created on: 15.06.2010 22:45:26 - Run 2 |
IE sollte jetzt wieder gehen. Wenn nicht teile mir das bitte mit Bitte
Bitte poste in Deiner nächsten Antwort Gmer.txt |
ich hab es runter geladen und es zeigt mir zum 3mal an das, dass programm einen fehler hat und beendet werden muss danach fährt er den pc automatisch runter. was soll ich machen??? bitte um rückmeldung |
kannst Du mir bitte die genaue Fehlermeldung mitteilen. Rootkitsuche mit SysProt
|
ich kann das nicht downloaden wenn ich auf den link geh dann unten auf download zeit er mit an die webseite kann nicht angezeigt werden. MFG Bilal |
HAT JETZT DOCH GEKLAPPT ABER MUSS ES TEIELEN WEIL ES ÜBER 100000 ZEICHEN HAT MIT "GMER" MFG BILAL GMER 1.0.15.15281 - hxxp://www.gmer.net Rootkit scan 2010-06-18 12:04:44 Windows 6.0.6002 Service Pack 2 Running: oxm7md72.exe; Driver: C:\Users\Bilal\AppData\Local\Temp\kwlcqpow.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x828E32D6] SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x828E34C8] SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x828E2F44] SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x828E36D0] ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!KeSetEvent + 209 81EC296C 3 Bytes [D6, 32, 8E] .text ntkrnlpa.exe!KeSetEvent + 20D 81EC2970 3 Bytes [C8, 34, 8E] .text ntkrnlpa.exe!KeSetEvent + 621 81EC2D84 3 Bytes [44, 2F, 8E] .text ntkrnlpa.exe!KeSetEvent + 6E5 81EC2E48 4 Bytes [D0, 36, 8E, 82] .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8EC08340, 0x3D9767, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[556] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[584] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wininit.exe[640] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\csrss.exe[652] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[680] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\services.exe[688] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\services.exe[688] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsass.exe[700] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\winlogon.exe[960] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1068] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1100] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7C, 71] {JL 0x73} .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9A, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [88, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [85, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8E, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A0, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9D, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [91, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [82, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [97, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [94, 71] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [7F, 71] {JG 0x73} .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8B, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7B, 71] {JNP 0x73} .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9A, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [87, 71] |
.text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8D, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9E, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [97, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1160] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8A, 71] .text C:\Windows\system32\AUDIODG.EXE[1292] ntdll.dll!NtTestAlert 77C15514 5 Bytes JMP 716F0000 .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1320] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\SLsvc.exe[1356] ntdll.dll!NtTestAlert 77C15514 5 Bytes JMP 716F0000 .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7D, 71] {JGE 0x73} .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [89, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [86, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8F, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [92, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [83, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [98, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [95, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [80, 71] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1428] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8C, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1484] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1528] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\IoctlSvc.exe[1552] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtClose + 4 77C14318 2 Bytes [80, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9E, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8C, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [89, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [92, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [AA, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A4, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [A1, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [95, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A7, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [86, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [9B, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [98, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [83, 71] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8F, 71] .text C:\Windows\system32\conime.exe[1632] kernel32.dll!LoadLibraryExW 77AF9109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\conime.exe[1632] USER32.dll!ChangeDisplaySettingsExA 76A06FE7 6 Bytes JMP 5F0D0F5A .text C:\Windows\system32\conime.exe[1632] USER32.dll!SetForegroundWindow 76A0B8A6 6 Bytes JMP 5F040F5A .text C:\Windows\system32\conime.exe[1632] USER32.dll!SetWindowPos 76A135E3 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\conime.exe[1632] USER32.dll!SetWindowPos + 4 76A135E7 2 Bytes [0B, 5F] .text C:\Windows\system32\conime.exe[1632] USER32.dll!ChangeDisplaySettingsExW 76A4A9E4 6 Bytes JMP 5F100F5A .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1672] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1716] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe[1792] ntdll.dll!NtTestAlert 77C15514 5 Bytes JMP 716F0000 .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1964] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7D, 71] {JGE 0x73} .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [89, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [86, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8F, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [92, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [83, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [98, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [95, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [80, 71] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1992] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8C, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[2004] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\PnkBstrA.exe[2068] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2084] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] |
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2096] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2136] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2164] ntdll.dll!NtTestAlert 77C15514 5 Bytes JMP 716F0000 .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2164] kernel32.dll!CreateThread + 1A 77B1C928 4 Bytes CALL 0044BC05 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools) .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtClose + 4 77C14318 2 Bytes [38, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [5B, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [A1, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [44, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [41, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [4A, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [9B, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [61, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [5E, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [4D, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [98, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [3E, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [58, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [55, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [3B, 71] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe[2264] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [47, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7B, 71] {JNP 0x73} .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [99, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [87, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [84, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8D, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9C, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [90, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [81, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [96, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [93, 71] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2296] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8A, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7D, 71] {JGE 0x73} .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9B, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [89, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [86, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8F, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9E, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [92, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [83, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [98, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [95, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [80, 71] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2332] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8C, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVECapSvc.exe[2396] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2424] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7B, 71] {JNP 0x73} .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [87, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [84, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8D, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [90, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [81, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [96, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [93, 71] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[2444] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8A, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7D, 71] {JGE 0x73} .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9B, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [89, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [86, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8F, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [92, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [83, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [98, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [95, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [80, 71] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[2504] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8C, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7D, 71] {JGE 0x73} .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [89, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [86, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [8F, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [92, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [83, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [98, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [95, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [80, 71] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe[2556] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8C, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[2764] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\HomeCinema\TV Enhance\Kernel\TV\TVESched.exe[2828] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\CLWatson.exe[2840] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtDeleteKey + 4 77C147C8 2 Bytes [A8, 71] {TEST AL, 0x71} .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtDeleteValueKey 77C147F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtDeleteValueKey + 4 77C147F8 2 Bytes [A2, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtRenameKey 77C150C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtRenameKey + 4 77C150C8 2 Bytes [9F, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtSetInformationFile 77C152E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtSetInformationFile + 4 77C152E8 2 Bytes [93, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtSetValueKey 77C15454 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtSetValueKey + 4 77C15458 2 Bytes [A5, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtTerminateProcess 77C154F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtTerminateProcess + 4 77C154F8 2 Bytes [84, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtWriteFile 77C15644 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtWriteFile + 4 77C15648 2 Bytes [99, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtWriteFileGather 77C15654 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtWriteFileGather + 4 77C15658 2 Bytes [96, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtWriteVirtualMemory 77C15674 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtWriteVirtualMemory + 4 77C15678 2 Bytes [81, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateUserProcess 77C15804 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] ntdll.dll!NtCreateUserProcess + 4 77C15808 2 Bytes [8D, 71] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] USER32.dll!ChangeDisplaySettingsExA 76A06FE7 6 Bytes JMP 5F0B0F5A .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] USER32.dll!SetForegroundWindow 76A0B8A6 6 Bytes JMP 5F040F5A .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] USER32.dll!SetWindowPos 76A135E3 3 Bytes [FF, 25, 1E] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] USER32.dll!SetWindowPos + 4 76A135E7 2 Bytes [09, 5F] .text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2852] USER32.dll!ChangeDisplaySettingsExW 76A4A9E4 6 Bytes JMP 5F0E0F5A .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtClose 77C14314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtClose + 4 77C14318 2 Bytes [7E, 71] {JLE 0x73} .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateFile 77C143D4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateFile + 4 77C143D8 2 Bytes [9C, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateKey 77C14414 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateKey + 4 77C14418 2 Bytes [AE, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateProcess 77C14494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateProcess + 4 77C14498 2 Bytes [8A, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateProcessEx 77C144A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateProcessEx + 4 77C144A8 2 Bytes [87, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateSection 77C144C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtCreateSection + 4 77C144C8 2 Bytes [90, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[2856] ntdll.dll!NtDeleteKey 77C147C4 3 Bytes [FF, 25, 1E] |
Alle Zeitangaben in WEZ +1. Es ist jetzt 09:38 Uhr. |
Copyright ©2000-2025, Trojaner-Board