GMER 1.0.15.14972 - http://www.gmer.net Rootkit scan 2009-05-20 19:29:27 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.15 ---- Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA7B734EA] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xA7B73581] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA7B73498] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xA7B734AC] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xA7B73595] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xA7B735C1] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xA7B7362F] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xA7B73619] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA7B7352A] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xA7B7365B] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xA7B7356D] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xA7B73470] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xA7B73484] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA7B734FE] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xA7B73697] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xA7B73603] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xA7B735ED] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xA7B735AB] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xA7B73683] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xA7B7366F] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xA7B734D6] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xA7B734C2] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xA7B735D7] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA7B73559] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xA7B73645] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA7B73540] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA7B73514] Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwYieldExecution 8050223C 7 Bytes JMP A7B73518 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!NtCreateFile 8056E2FC 5 Bytes JMP A7B734EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!NtMapViewOfSection 805A7500 7 Bytes JMP A7B7352E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A8316 5 Bytes JMP A7B73544 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805ADA94 7 Bytes JMP A7B73502 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!NtOpenProcess 805C1322 5 Bytes JMP A7B73474 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!NtOpenThread 805C15AE 5 Bytes JMP A7B73488 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!NtSetInformationProcess 805C3DE0 5 Bytes JMP A7B734C6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C73F6 7 Bytes JMP A7B734B0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwCreateProcess 805C74AC 5 Bytes JMP A7B7349C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwSetContextThread 805C79B6 5 Bytes JMP A7B734DA \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwTerminateProcess 805C8CB6 5 Bytes JMP A7B7355D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwQueryValueKey 80618568 7 Bytes JMP A7B735F1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwSetValueKey 806188B6 7 Bytes JMP A7B735DB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwUnloadKey 80618BE0 7 Bytes JMP A7B73649 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 8061947E 7 Bytes JMP A7B73607 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwRenameKey 80619D52 7 Bytes JMP A7B735AF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwCreateKey 8061A330 5 Bytes JMP A7B73585 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwDeleteKey 8061A7C0 7 Bytes JMP A7B73599 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwDeleteValueKey 8061A990 7 Bytes JMP A7B735C5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwEnumerateKey 8061AB70 7 Bytes JMP A7B73633 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8061ADDA 7 Bytes JMP A7B7361D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwOpenKey 8061B702 5 Bytes JMP A7B73571 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwQueryKey 8061BA28 7 Bytes JMP A7B7369B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwRestoreKey 8061BCE8 5 Bytes JMP A7B73673 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwReplaceKey 8061C3DC 5 Bytes JMP A7B73687 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8061C4F6 5 Bytes JMP A7B7365F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ---- User code sections - GMER 1.0.15 ---- .text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[352] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.) .text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[352] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.) .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 002B000A .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 002B0087 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 002B006C .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 002B0F9E .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 002B0051 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 002B0040 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 002B0F61 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 002B00B3 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 002B00DF .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 002B00CE .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002B00FA .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 002B0FAF .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 002B0FE5 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 002B00A2 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 002B0025 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 002B0FD4 .text C:\WINDOWS\System32\svchost.exe[404] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 002B0F50 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 003A0FC3 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 003A0065 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 003A0FD4 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 003A0FE5 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 003A0054 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 003A0000 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 003A0FB2 .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [5A, 88] .text C:\WINDOWS\System32\svchost.exe[404] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 003A002F .text C:\WINDOWS\System32\svchost.exe[404] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 004F0049 .text C:\WINDOWS\System32\svchost.exe[404] msvcrt.dll!system 77C293C7 5 Bytes JMP 004F0038 .text C:\WINDOWS\System32\svchost.exe[404] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 004F000C .text C:\WINDOWS\System32\svchost.exe[404] msvcrt.dll!_open 77C2F566 5 Bytes JMP 004F0FEF .text C:\WINDOWS\System32\svchost.exe[404] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 004F0027 .text C:\WINDOWS\System32\svchost.exe[404] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 004F0FD2 .text C:\WINDOWS\System32\svchost.exe[404] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00220FEF .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0000 .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0F8D .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE0078 .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0F9E .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE005B .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0FB9 .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F6B .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE0F7C .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE00C4 .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE0F2B .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE0F10 .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE004A .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0FEF .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE009D .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE002F .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE0FDE .text C:\WINDOWS\system32\services.exe[964] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE0F50 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009A002C .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009A0FA5 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009A0011 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009A0FE5 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009A0062 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009A0000 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 009A0051 .text C:\WINDOWS\system32\services.exe[964] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009A0FCA .text C:\WINDOWS\system32\services.exe[964] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00990FBE .text C:\WINDOWS\system32\services.exe[964] msvcrt.dll!system 77C293C7 5 Bytes JMP 00990053 .text C:\WINDOWS\system32\services.exe[964] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00990FE3 .text C:\WINDOWS\system32\services.exe[964] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00990000 .text C:\WINDOWS\system32\services.exe[964] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00990042 .text C:\WINDOWS\system32\services.exe[964] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00990011 .text C:\WINDOWS\system32\services.exe[964] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0097000A .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C10FE5 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C10058 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C10F63 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C1003D .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C10F80 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C10022 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C1008E .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C10F3C .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C100CE .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C10F2B .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C100DF .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C10F9B .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C10000 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C10073 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C10011 .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C10FCA .text C:\WINDOWS\system32\lsass.exe[976] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C1009F .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C00025 .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C0007D .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C00FD4 .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C00FE5 .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C0006C .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C00000 .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00C00051 .text C:\WINDOWS\system32\lsass.exe[976] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C00036 .text C:\WINDOWS\system32\lsass.exe[976] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BF0036 .text C:\WINDOWS\system32\lsass.exe[976] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BF0FAB .text C:\WINDOWS\system32\lsass.exe[976] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BF0FC6 .text C:\WINDOWS\system32\lsass.exe[976] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BF0FEF .text C:\WINDOWS\system32\lsass.exe[976] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BF001B .text C:\WINDOWS\system32\lsass.exe[976] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BF0000 .text C:\WINDOWS\system32\lsass.exe[976] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BE0000 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00AD000A .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00AD0F70 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00AD005B .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00AD0F8D .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00AD004A .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00AD0FB9 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00AD0F42 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00AD0F53 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00AD0F0C .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00AD0F1D .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00AD00C0 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00AD0FA8 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00AD0FEF .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00AD0080 .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00AD002F .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00AD0FDE .text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00AD00A5 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00AC0FC3 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00AC0065 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00AC000A .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00AC0FD4 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00AC0054 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00AC0FE5 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00AC0FB2 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [CC, 88] .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00AC0039 .text C:\WINDOWS\system32\svchost.exe[1144] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00AB0FBE .text C:\WINDOWS\system32\svchost.exe[1144] msvcrt.dll!system 77C293C7 5 Bytes JMP 00AB0FE3 .text C:\WINDOWS\system32\svchost.exe[1144] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00AB0038 .text C:\WINDOWS\system32\svchost.exe[1144] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00AB000C .text C:\WINDOWS\system32\svchost.exe[1144] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00AB0053 .text C:\WINDOWS\system32\svchost.exe[1144] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00AB001D .text C:\WINDOWS\system32\svchost.exe[1144] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00AA0000 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B40000 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B40F7E .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B40073 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B40FA5 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B40062 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B4002C .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B40F48 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B40084 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B40F2D .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B400C6 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B40F1C .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B40047 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B40FE5 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B40F59 .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B4001B .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B40FCA .text C:\WINDOWS\system32\svchost.exe[1224] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B400AB .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B3001E .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B30039 .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B30FC3 .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B30FDE .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B30F72 .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B30FEF .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B30F8D .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D3, 88] .text C:\WINDOWS\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B30FB2 .text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B20F92 .text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B20FB7 .text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B20027 .text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B20FEF .text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B20FC8 .text C:\WINDOWS\system32\svchost.exe[1224] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B2000C .text C:\WINDOWS\system32\svchost.exe[1224] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B10FEF .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 028A0FEF .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 028A0F6D .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 028A0062 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 028A0051 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 028A0F94 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 028A002F .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 028A008E .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 028A007D .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 028A00CB .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 028A00BA .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 028A0F21 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 028A0040 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 028A0FCA .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 028A0F52 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 028A0FB9 .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 028A000A .text C:\WINDOWS\System32\svchost.exe[1264] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 028A009F .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02880FBC .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02880FA1 .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02880FCD .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02880FDE .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0288005E .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02880FEF .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02880043 .text C:\WINDOWS\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02880032 .text C:\WINDOWS\System32\svchost.exe[1264] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02870FB9 .text C:\WINDOWS\System32\svchost.exe[1264] msvcrt.dll!system 77C293C7 5 Bytes JMP 0287003A .text C:\WINDOWS\System32\svchost.exe[1264] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02870018 .text C:\WINDOWS\System32\svchost.exe[1264] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02870FEF .text C:\WINDOWS\System32\svchost.exe[1264] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02870029 .text C:\WINDOWS\System32\svchost.exe[1264] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02870FDE .text C:\WINDOWS\System32\svchost.exe[1264] WS2_32.dll!socket 71AB4211 5 Bytes JMP 025E000A .text C:\WINDOWS\System32\svchost.exe[1264] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 02890FEF .text C:\WINDOWS\System32\svchost.exe[1264] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 02890000 .text C:\WINDOWS\System32\svchost.exe[1264] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 02890011 .text C:\WINDOWS\System32\svchost.exe[1264] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 02890022 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009C0000 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009C0F6F .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009C006E .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009C0F94 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009C0051 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009C0040 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009C0095 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009C0F4D .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009C00C1 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009C00B0 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009C0F0D .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009C0FB9 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009C001B .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009C0F5E .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009C0FD4 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009C0FE5 .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009C0F3C .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009B0011 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009B004E .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009B0000 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009B0FD4 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009B0F91 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009B0FE5 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 009B0033 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009B0022 .text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009A0044 .text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 009A0FAF .text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009A0FEF .text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009A0000 .text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009A0FCA .text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009A001D .text C:\WINDOWS\system32\svchost.exe[1312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00990000 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B80FEF .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B800B8 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B8009D .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B80082 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B8005B .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B8002F .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B800F0 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B80FA8 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B8011C .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B80F8D .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B80F68 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B8004A .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B80FDE .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B800C9 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B8001E .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B80FC3 .text C:\WINDOWS\system32\svchost.exe[1436] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B8010B .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B70FE5 .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B70F94 .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B70036 .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B7001B .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B70047 .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B70000 .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B70FA5 .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D7, 88] .text C:\WINDOWS\system32\svchost.exe[1436] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B70FCA .text C:\WINDOWS\system32\svchost.exe[1436] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B60FA8 .text C:\WINDOWS\system32\svchost.exe[1436] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B6003D .text C:\WINDOWS\system32\svchost.exe[1436] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B60022 .text C:\WINDOWS\system32\svchost.exe[1436] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B60000 .text C:\WINDOWS\system32\svchost.exe[1436] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B60FCD .text C:\WINDOWS\system32\svchost.exe[1436] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B60011 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009C0000 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009C0F83 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009C0F94 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009C006E .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009C0FA5 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009C0FDB .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009C00AE .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009C009D .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009C00DA .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009C0F4B .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009C0F26 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009C0FCA .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009C0011 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009C0F72 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009C0047 .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009C002C .text C:\WINDOWS\system32\svchost.exe[1492] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009C00C9 .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009B0FA8 .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009B0F61 .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009B0FC3 .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009B0FD4 .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009B0F72 .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009B0FEF .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 009B0F8D .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [BB, 88] .text C:\WINDOWS\system32\svchost.exe[1492] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009B0014 .text C:\WINDOWS\system32\svchost.exe[1492] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009A0047 .text C:\WINDOWS\system32\svchost.exe[1492] msvcrt.dll!system 77C293C7 5 Bytes JMP 009A0FBC .text C:\WINDOWS\system32\svchost.exe[1492] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009A0FDE .text C:\WINDOWS\system32\svchost.exe[1492] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009A0FEF .text C:\WINDOWS\system32\svchost.exe[1492] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009A0FCD .text C:\WINDOWS\system32\svchost.exe[1492] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009A0018 .text C:\WINDOWS\system32\svchost.exe[1492] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0099000A .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B90000 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B90F52 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B90047 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B90F6D .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B90F8A .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B90036 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B90F12 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B90F2D .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B90EE6 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B9007F .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B90ED5 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B90FA5 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B90FDB .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B90058 .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B9001B .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B90FCA .text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B90F01 .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00920040 .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00920065 .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0092002F .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0092000A .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00920F9E .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00920FEF .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00920FB9 .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [B2, 88] {MOV DL, 0x88} .text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00920FCA .text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0091003D .text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!system 77C293C7 5 Bytes JMP 00910FB2 .text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00910011 .text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00910000 .text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00910022 .text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00910FE3 .text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 0093000A .text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 0093001B .text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlA 78070BCA 3 Bytes JMP 0093002C .text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlA + 4 78070BCE 1 Byte [88] .text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00930051 .text C:\WINDOWS\system32\svchost.exe[1956] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00900FE5 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A000A .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0F81 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0F92 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A006C .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0FAF .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0FCA .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A00B8 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A00A7 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0F29 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F3A .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001A00DD .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001A005B .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001A001B .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001A0F70 .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001A0FDB .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001A002C .text C:\WINDOWS\Explorer.EXE[2572] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001A0F55 .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00290FB9 .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00290040 .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00290FCA .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00290FDB .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00290F83 .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00290000 .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00290F94 .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [49, 88] .text C:\WINDOWS\Explorer.EXE[2572] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00290025 .text C:\WINDOWS\Explorer.EXE[2572] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002A0FBE .text C:\WINDOWS\Explorer.EXE[2572] msvcrt.dll!system 77C293C7 5 Bytes JMP 002A0053 .text C:\WINDOWS\Explorer.EXE[2572] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002A0FE3 .text C:\WINDOWS\Explorer.EXE[2572] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002A0000 .text C:\WINDOWS\Explorer.EXE[2572] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002A0038 .text C:\WINDOWS\Explorer.EXE[2572] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002A001D .text C:\WINDOWS\Explorer.EXE[2572] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C0000 .text C:\WINDOWS\Explorer.EXE[2572] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C0FEF .text C:\WINDOWS\Explorer.EXE[2572] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C0FDE .text C:\WINDOWS\Explorer.EXE[2572] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 002C0039 .text C:\WINDOWS\Explorer.EXE[2572] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01960FEF ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Documents and Settings\Abbie\Desktop\gmer\gmer.exe[164] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Documents and Settings\Abbie\Desktop\gmer\gmer.exe[164] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Documents and Settings\Abbie\Desktop\gmer\gmer.exe[164] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00802C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Documents and Settings\Abbie\Desktop\gmer\gmer.exe[164] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\stsystra.exe[204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A62E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\stsystra.exe[204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A62C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\stsystra.exe[204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A62C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\stsystra.exe[204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A62C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[764] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A62E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[764] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A62C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[764] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A62C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[764] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A62C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\ctfmon.exe[1388] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00512E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\ctfmon.exe[1388] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00512C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\ctfmon.exe[1388] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00512C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\ctfmon.exe[1388] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00512C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\WLTRAY.exe[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B72E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\WLTRAY.exe[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B72C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\WLTRAY.exe[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00B72C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\WINDOWS\system32\WLTRAY.exe[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B72C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00E02E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00E02C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00E02C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00E02C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT c:\PROGRA~1\mcafee.com\agent\mcagent.exe[3688] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B62E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT c:\PROGRA~1\mcafee.com\agent\mcagent.exe[3688] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B62C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT c:\PROGRA~1\mcafee.com\agent\mcagent.exe[3688] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00B62C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) IAT c:\PROGRA~1\mcafee.com\agent\mcagent.exe[3688] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B62C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.) AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.) Device \FileSystem\Fastfat \Fat A67D5D20 AttachedDevice \FileSystem\Fastfat \Fat SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions) ---- EOF - GMER 1.0.15 ----