Jeg har også lavet en Gmer log. Jeg håber jeg har leveret nok information, til at få lidt hjælp.
GMER 1.0.15.15087 -
http://www.gmer.netRootkit scan 2009-09-28 11:19:23
Windows 5.1.2600 Service Pack 3
Running: a12nc.exe; Driver: C:\DOCUME~1\Ejer\LOKALE~1\Temp\uwloypow.sys
---- System - GMER 1.0.15 ----
SSDT spcl.sys ZwCreateKey [0xF74B50E0]
SSDT spcl.sys ZwEnumerateKey [0xF74D3CA4]
SSDT spcl.sys ZwEnumerateValueKey [0xF74D4032]
SSDT spcl.sys ZwOpenKey [0xF74B50C0]
SSDT spcl.sys ZwQueryKey [0xF74D410A]
SSDT spcl.sys ZwQueryValueKey [0xF74D3F8A]
SSDT spcl.sys ZwSetValueKey [0xF74D419C]
SSDT \??\C:\Programmer\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA8FEB0B0]
INT 0x62 ? 8636DBF8
INT 0x63 ? 8616CBF8
INT 0x63 ? 8616CBF8
INT 0x63 ? 8616CBF8
INT 0x73 ? 8616CBF8
INT 0x82 ? 8636DBF8
INT 0x94 ? 8616CBF8
INT 0xB4 ? 8616CBF8
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA9C1CAC1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA9C1CAEB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xA9C1CA55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xA9C1CA81]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA9C1CB15]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA9C1CAD5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xA9C1CA6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA9C1CAAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA9C1CB2B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA9C1CAFF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution 804F0EA6 7 Bytes JMP A9C1CB03 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056CDC0 5 Bytes JMP A9C1CAC5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80571CB1 7 Bytes JMP A9C1CAD9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 805736E6 5 Bytes JMP A9C1CB2F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80573B61 7 Bytes JMP A9C1CB19 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805822EC 5 Bytes JMP A9C1CAB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80592D5C 7 Bytes JMP A9C1CA85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 805952CA 7 Bytes JMP A9C1CA59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B136A 5 Bytes JMP A9C1CAEF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064E77C 7 Bytes JMP A9C1CA6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? spcl.sys Den angivne fil blev ikke fundet. !
.text USBPORT.SYS!DllUnload F655F8AC 5 Bytes JMP 8616C1D8
.text avqkvl7v.SYS F5D07386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text avqkvl7v.SYS F5D073AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text avqkvl7v.SYS F5D073C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text avqkvl7v.SYS F5D073C9 1 Byte [30]
.text avqkvl7v.SYS F5D073C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EE0000
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EE0040
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EE0F4B
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EE0F5C
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EE0F83
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EE0FA5
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EE0062
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EE0051
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EE0EDA
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EE0EF5
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EE008E
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EE0F94
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EE0FE5
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EE0F26
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EE0011
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EE0FC0
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EE0073
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00ED0FCD
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00ED0FA1
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00ED0FDE
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00ED0FEF
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00ED0FB2
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00ED000A
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00ED004A
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00ED0039
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00EC0FC3
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] msvcrt.dll!system 77C193C7 5 Bytes JMP 00EC004E
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00EC0022
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00EC0FEF
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00EC0033
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00EC0FDE
.text C:\Programmer\McAfee\Common Framework\naPrdMgr.exe[360] WS2_32.dll!socket 71A84211 5 Bytes JMP 00EB0000
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE000A
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE0F92
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0087
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE0076
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0065
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0FC3
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE0F77
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE00C9
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE0F5C
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE00F5
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE0106
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE004A
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0FE5
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE00AC
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FD4
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0025
.text C:\WINDOWS\Explorer.EXE[516] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE00E4
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00BD0FCA
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00BD0047
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00BD001B
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00BD0FE5
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00BD0036
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00BD0F94
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [DE, 88]
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00BD0FAF
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00BC0FC1
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!system 77C193C7 5 Bytes JMP 00BC0FD2
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00BC0038
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00BC0000
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00BC0FE3
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00BC001D
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenA 40B3D688 5 Bytes JMP 00BA0000
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenW 40B3DB01 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenUrlA 40B3F39C 5 Bytes JMP 00BA0025
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenUrlW 40B86F37 5 Bytes JMP 00BA0036
.text C:\WINDOWS\Explorer.EXE[516] WS2_32.dll!socket 71A84211 5 Bytes JMP 00E70FEF
.text C:\WINDOWS\system32\SearchIndexer.exe[676] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00070056
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00070F61
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070F72
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00070F8D
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00070025
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00070F1A
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00070F2B
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000700B3
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 000700A2
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00070EFF
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00070F9E
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00070F46
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00070FAF
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[936] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00070087
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00060FCA
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00060F68
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00060FE5
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 0006001B
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00060F79
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 0006000A
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00060F94
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [27, 88]
.text C:\WINDOWS\system32\services.exe[936] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00060FAF
.text C:\WINDOWS\system32\services.exe[936] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00050F9A
.text C:\WINDOWS\system32\services.exe[936] msvcrt.dll!system 77C193C7 5 Bytes JMP 00050FAB
.text C:\WINDOWS\system32\services.exe[936] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00050FD7
.text C:\WINDOWS\system32\services.exe[936] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[936] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00050FBC
.text C:\WINDOWS\system32\services.exe[936] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00050011
.text C:\WINDOWS\system32\services.exe[936] WS2_32.dll!socket 71A84211 5 Bytes JMP 00040FE5
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F50FEF
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F50089
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F50064
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F50F8A
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F50F9B
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F50FAC
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F500C1
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F50F6F
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F50F39
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F500D2
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F500E3
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F50033
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F50000
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F5009A
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F50022
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F50011
.text C:\WINDOWS\system32\lsass.exe[948] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F50F5E
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00F4002C
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00F40F9E
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00F4001B
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00F40FE5
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00F40FAF
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00F40000
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00F40FC0
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [15, 89]
.text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00F40047
.text C:\WINDOWS\system32\lsass.exe[948] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00F30042
.text C:\WINDOWS\system32\lsass.exe[948] msvcrt.dll!system 77C193C7 5 Bytes JMP 00F30FB7
.text C:\WINDOWS\system32\lsass.exe[948] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00F30016
.text C:\WINDOWS\system32\lsass.exe[948] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00F30FEF
.text C:\WINDOWS\system32\lsass.exe[948] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00F30027
.text C:\WINDOWS\system32\lsass.exe[948] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00F30FDE
.text C:\WINDOWS\system32\lsass.exe[948] WS2_32.dll!socket 71A84211 5 Bytes JMP 00C70FE5
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F8000A
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F80F92
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80FA3
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80FB4
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F8007D
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F80062
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80F70
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F80F81
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F800F5
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F800E4
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F80106
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F80FDB
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80025
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F800A2
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F80047
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F80036
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F800C9
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00F70FDB
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00F70F8A
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00F7002C
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00F70011
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00F70F9B
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00F70000
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00F70047
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00F70FCA
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00F60070
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!system 77C193C7 5 Bytes JMP 00F60FDB
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00F6003A
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00F6000C
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00F60055
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00F6001D
.text C:\WINDOWS\system32\svchost.exe[1100] WS2_32.dll!socket 71A84211 5 Bytes JMP 00F50000
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C70000
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C70F80
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C70F91
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C70FAC
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C70069
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C70044
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C70F4D
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C70F5E
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C700C1
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C70F28
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C700D2
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C70FC7
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C70011
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C70F6F
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C70033
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C70022
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C700B0
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00C60051
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00C60FC0
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00C60036
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00C60025
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00C60FDB
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00C6000A
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 00C60073
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00C60062
.text C:\WINDOWS\system32\svchost.exe[1180] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00C50025
.text C:\WINDOWS\system32\svchost.exe[1180] msvcrt.dll!system 77C193C7 5 Bytes JMP 00C50F9A
.text C:\WINDOWS\system32\svchost.exe[1180] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00C50FC6
.text C:\WINDOWS\system32\svchost.exe[1180] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00C50000
.text C:\WINDOWS\system32\svchost.exe[1180] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00C50FAB
.text C:\WINDOWS\system32\svchost.exe[1180] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00C50FE3
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!socket 71A84211 5 Bytes JMP 00C40000
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02290FEF
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!VirtualProtectEx 7C801A61 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02290065
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02290054
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02290043
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02290F86
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0229001E
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02290F44
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02290F55
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 022900C2
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02290F29
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02290F04
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02290F97
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02290FDE
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02290080
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02290FB2
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02290FCD
.text C:\WINDOWS\System32\svchost.exe[1220] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 022900A7
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 02280FB9
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 02280051
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 0228000A
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 02280FD4
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 02280F94
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 02280FEF
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 0228002C
.text C:\WINDOWS\System32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 0228001B
.text C:\WINDOWS\System32\svchost.exe[1220] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 02270FB7
.text C:\WINDOWS\System32\svchost.exe[1220] msvcrt.dll!system 77C193C7 5 Bytes JMP 02270042
.text C:\WINDOWS\System32\svchost.exe[1220] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 02270027
.text C:\WINDOWS\System32\svchost.exe[1220] msvcrt.dll!_open 77C1F566 5 Bytes JMP 02270FEF
.text C:\WINDOWS\System32\svchost.exe[1220] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 02270FD2
.text C:\WINDOWS\System32\svchost.exe[1220] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 0227000C
.text C:\WINDOWS\System32\svchost.exe[1220] WS2_32.dll!socket 71A84211 5 Bytes JMP 02260000
.text C:\WINDOWS\System32\svchost.exe[1220] WININET.dll!InternetOpenA 40B3D688 5 Bytes JMP 01E40000
.text C:\WINDOWS\System32\svchost.exe[1220] WININET.dll!InternetOpenW 40B3DB01 5 Bytes JMP 01E4001B
.text C:\WINDOWS\System32\svchost.exe[1220] WININET.dll!InternetOpenUrlA 40B3F39C 5 Bytes JMP 01E40040
.text C:\WINDOWS\System32\svchost.exe[1220] WININET.dll!InternetOpenUrlW 40B86F37 5 Bytes JMP 01E40051
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 007C0FEF
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 007C0087
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 007C0076
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 007C005B
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 007C0F9E
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 007C002F
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007C00DA
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007C00BF
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007C0F55
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007C0F66
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 007C0109
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 007C0040
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 007C0014
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 007C00A2
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 007C0FB9
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 007C0FDE
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 007C0F77
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 007B002C
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 007B0073
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 007B0FDB
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 007B001B
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 007B0FC0
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 007B0000
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyW 77DEBA55 5 Bytes JMP 007B0062
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 007B0047
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 007A0FA1
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!system 77C193C7 5 Bytes JMP 007A002C
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 007A0FCD
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_open 77C1F566 5 Bytes JMP 007A0FEF
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 007A0FBC
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 007A0FDE
.text C:\WINDOWS\system32\svchost.exe[1268] WS2_32.dll!socket 71A84211 5 Bytes JMP 00790000
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A1000A
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10F66
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A1005B
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10F8D
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A10F9E
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A10FB9
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A10F1D
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A10F2E
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A10F02
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A1009B
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A100B6
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A10040
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A1001B
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A10F4B
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A10FCA
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A10FDB
.text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A1008A
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00A00FC0
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00A00F72
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 00A0001B
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 00A0000A
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00A00F83
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00A00FEF
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00A00F94
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [C1, 88]
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00A00FA5
.text C:\WINDOWS\system32\svchost.exe[1416] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 009F0053
.text C:\WINDOWS\system32\svchost.exe[1416] msvcrt.dll!system 77C193C7 5 Bytes JMP 009F0FD2
.text C:\WINDOWS\system32\svchost.exe[1416] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 009F0027
.text C:\WINDOWS\system32\svchost.exe[1416] msvcrt.dll!_open 77C1F566 5 Bytes JMP 009F0FE3
.text C:\WINDOWS\system32\svchost.exe[1416] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 009F0038
.text C:\WINDOWS\system32\svchost.exe[1416] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 009F000C
.text C:\WINDOWS\system32\svchost.exe[1416] WS2_32.dll!socket 71A84211 5 Bytes JMP 009E0000
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C60000
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C60060
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C60F61
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C60F7C
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C60F8D
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C60FB9
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C6008C
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C60F50
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C600A7
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C60F0E
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C60EF3
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C60FA8
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C60FEF
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C60071
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C60FD4
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C60025
.text C:\WINDOWS\system32\svchost.exe[1884] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C60F29
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegOpenKeyExW 77DC6AAF 5 Bytes JMP 00980FCA
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegCreateKeyExW 77DC776C 5 Bytes JMP 00980054
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegOpenKeyExA 77DC7852 5 Bytes JMP 0098001B
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegOpenKeyW 77DC7946 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegCreateKeyExA 77DCE9F4 5 Bytes JMP 00980F97
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegOpenKeyA 77DCEFC8 5 Bytes JMP 00980FEF
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegCreateKeyW 77DEBA55 2 Bytes JMP 00980FA8
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegCreateKeyW + 3 77DEBA58 2 Bytes [B9, 88]
.text C:\WINDOWS\system32\svchost.exe[1884] ADVAPI32.dll!RegCreateKeyA 77DEBCF3 5 Bytes JMP 00980FB9
.text C:\WINDOWS\system32\svchost.exe[1884] msvcrt.dll!_wsystem 77C1931E 5 Bytes JMP 00970F9C
.text C:\WINDOWS\system32\svchost.exe[1884] msvcrt.dll!system 77C193C7 5 Bytes JMP 00970027
.text C:\WINDOWS\system32\svchost.exe[1884] msvcrt.dll!_creat 77C1D40F 5 Bytes JMP 00970FD2
.text C:\WINDOWS\system32\svchost.exe[1884] msvcrt.dll!_open 77C1F566 5 Bytes JMP 00970000
.text C:\WINDOWS\system32\svchost.exe[1884] msvcrt.dll!_wcreat 77C1FC9B 5 Bytes JMP 00970FB7
.text C:\WINDOWS\system32\svchost.exe[1884] msvcrt.dll!_wopen 77C20055 5 Bytes JMP 00970FE3
.text C:\WINDOWS\system32\svchost.exe[1884] WININET.dll!InternetOpenA 40B3D688 5 Bytes JMP 00950FEF
.text C:\WINDOWS\system32\svchost.exe[1884] WININET.dll!InternetOpenW 40B3DB01 5 Bytes JMP 00950FDE
.text C:\WINDOWS\system32\svchost.exe[1884] WININET.dll!InternetOpenUrlA 40B3F39C 5 Bytes JMP 00950014
.text C:\WINDOWS\system32\svchost.exe[1884] WININET.dll!InternetOpenUrlW 40B86F37 5 Bytes JMP 00950FC3
.text C:\WINDOWS\system32\svchost.exe[1884] WS2_32.dll!socket 71A84211 5 Bytes JMP 00960FE5
.text C:\Programmer\McAfee\Common Framework\FrameworkService.exe[2016] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 010E0FEF
.text C:\Programmer\McAfee\Common Framework\FrameworkService.exe[2016] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 010E0F86
.text C:\Programmer\McAfee\Common Framework\FrameworkService.exe[2016] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 010E0F97
.text C:\Programmer\McAfee\Common Framework\FrameworkService.exe[2016] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 010E0065
.text C:\Programmer\McAfee\Common Framework\FrameworkService.exe[2016] kernel32.dll!LoadLibraryExA