Re: Proces WmPrvSE.exe neúměrně vytěžuje procesor
Napsal: 02 zář 2011 21:36
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-09-02 22:35:21
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0000
Running: gmer.exe; Driver: C:\Users\Honza\AppData\Local\Temp\pwliafod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8F736202]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8F7387F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8F738848]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8F73895E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8F738746]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8F738898]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8F73879A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8F73890C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8F736226]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8F735FF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8F73624A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8F738D56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8F736CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8F738820]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8F738870]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8F738988]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8F738772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8F7388D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8F7387C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8F738936]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8F736BA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8F73626E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8F736292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8F73604A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8F736186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8F736162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8F7361AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8F7362B6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8E3AA398]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!KeInsertQueue + 2FD 824AE8F4 4 Bytes [02, 62, 73, 8F]
.text ntoskrnl.exe!KeInsertQueue + 3C1 824AE9B8 8 Bytes [F0, 87, 73, 8F, 48, 88, 73, ...] {LOCK XCHG [EBX-0x71], ESI; DEC EAX; MOV [EBX-0x71], DH}
.text ntoskrnl.exe!KeInsertQueue + 3CD 824AE9C4 4 Bytes [5E, 89, 73, 8F] {POP ESI; MOV [EBX-0x71], ESI}
.text ntoskrnl.exe!KeInsertQueue + 3E5 824AE9DC 4 Bytes [46, 87, 73, 8F] {INC ESI; XCHG [EBX-0x71], ESI}
.text ntoskrnl.exe!KeInsertQueue + 405 824AE9FC 8 Bytes [98, 88, 73, 8F, 9A, 87, 73, ...]
.text ...
PAGE ntoskrnl.exe!ObMakeTemporaryObject 825E4E46 5 Bytes JMP 8E3A5D4C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 110 8262E54F 4 Bytes CALL 8F73734B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ObInsertObject 82632A1C 5 Bytes JMP 8E3A77F2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwAlpcSendWaitReceivePort + 121 8265C013 4 Bytes CALL 8F737361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 826C9E84 7 Bytes JMP 8E3AA39C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? System32\drivers\jqbdgmq.sys Systém nemůže nalézt uvedenou cestu. !
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8D407340, 0x3EE1D7, 0xE8000020]
.text win32k.sys!EngCreateRectRgn + 4537 9981FC80 5 Bytes JMP 8F739440 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreatePalette + C20 99838EA9 5 Bytes JMP 8F739E0C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 4A1 99839C95 5 Bytes JMP 8F739F72 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 8C03 998423F7 5 Bytes JMP 8F738D8C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 616 9984334E 5 Bytes JMP 8F739BD8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 3103 9984EA94 5 Bytes JMP 8F739316 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 456E 9984FEFF 5 Bytes JMP 8F738F34 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 119C6 99869A35 5 Bytes JMP 8F739180 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 11A1A 99869A89 5 Bytes JMP 8F739326 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 377F 99890A8E 5 Bytes JMP 8F739B64 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 60DE 998933ED 5 Bytes JMP 8F738E58 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 4D3F 99899D2E 5 Bytes JMP 8F738FA4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 2B42 998A41CC 5 Bytes JMP 8F73A014 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStrokePath + 5FF 998A70B4 5 Bytes JMP 8F738E70 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 81C 998C54E5 5 Bytes JMP 8F739D54 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 6EEA 998CBBB3 5 Bytes JMP 8F739BAE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCopyBits + B0F 998CF32A 5 Bytes JMP 8F739CA2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_vEnumStart + 4728 998D6C49 5 Bytes JMP 8F738EF0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + E80 998F51BC 5 Bytes JMP 8F7390AE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_bEnum + 248 998FAA3A 5 Bytes JMP 8F739008 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 26D9 998FE572 5 Bytes JMP 8F739ECA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + A0F 9991CA97 5 Bytes JMP 8F73903E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + D269 999292F1 5 Bytes JMP 8F7390E8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF 9EC5B03F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 9EC5B0AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 9EC5B0AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 9EC5B130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 9EC5B137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
? C:\Windows\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !
? C:\Users\Honza\AppData\Local\Temp\catchme.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\System32\spoolsv.exe[232] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\spoolsv.exe[232] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\spoolsv.exe[232] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000801F8
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00930600
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00930804
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00930A08
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 009301F8
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 009303FC
.text C:\Windows\system32\svchost.exe[448] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[448] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[448] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[448] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00200600
.text C:\Windows\system32\svchost.exe[448] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00200804
.text C:\Windows\system32\svchost.exe[448] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00200A08
.text C:\Windows\system32\svchost.exe[448] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 002001F8
.text C:\Windows\system32\svchost.exe[448] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 002003FC
.text C:\Windows\system32\csrss.exe[624] KERNEL32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[676] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[676] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[676] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[676] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[676] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[676] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[676] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[676] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[688] KERNEL32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\services.exe[720] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[720] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[720] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[720] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[720] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[720] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[720] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[720] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\lsass.exe[732] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00080600
.text C:\Windows\system32\lsass.exe[732] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\lsass.exe[732] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\lsass.exe[732] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\lsass.exe[732] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsm.exe[740] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[740] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[740] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 001C01F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 001C03FC
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!RegOpenKeyExA 75CD7C42 5 Bytes JMP 00043EEE C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Windows Live Family Safety Service/Microsoft Corporation)
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 001E03FC
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 001E0600
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 001E1014
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 001E0804
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 001E0A08
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 001E0C0C
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 001E0E10
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 001E01F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 001F0600
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 001F0804
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 001F0A08
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001F01F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001F03FC
.text C:\Windows\system32\winlogon.exe[816] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[816] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[816] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 001503FC
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00150600
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00151014
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00150804
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00150A08
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00150C0C
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00150E10
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 001501F8
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00160600
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00160804
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWindowsHookEx 761598DB 3 Bytes JMP 00160A08
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWindowsHookEx + 4 761598DF 1 Byte [8A]
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001601F8
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWinEvent 7615C06F 3 Bytes JMP 001603FC
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWinEvent + 4 7615C073 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[928] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[928] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00390600
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00390804
.text C:\Windows\system32\svchost.exe[928] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00390A08
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 003901F8
.text C:\Windows\system32\svchost.exe[928] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 003903FC
.text C:\Windows\system32\nvvsvc.exe[984] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\nvvsvc.exe[984] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 001503FC
.text C:\Windows\system32\nvvsvc.exe[984] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00170600
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00170804
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00170A08
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001701F8
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001703FC
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 001803FC
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00180600
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00181014
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00180804
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00180A08
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00180C0C
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00180E10
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1012] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1012] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1012] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00120600
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00120804
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00120A08
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001201F8
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001203FC
.text C:\Windows\System32\svchost.exe[1048] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1048] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1048] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00AB0600
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00AB0804
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00AB0A08
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 00AB01F8
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 00AB03FC
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00140600
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00140804
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00140A08
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001401F8
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001403FC
.text C:\Windows\System32\svchost.exe[1160] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1160] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1160] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000801F8
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00E80600
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00E80804
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00E80A08
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 00E801F8
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 00E803FC
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1172] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00180600
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00180804
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\AUDIODG.EXE[1296] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1316] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1316] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1316] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 000E0600
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 000E0804
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 000E0A08
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000E01F8
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000E03FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00070600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00070804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00070A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!CreateServiceA
Rootkit scan 2011-09-02 22:35:21
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0000
Running: gmer.exe; Driver: C:\Users\Honza\AppData\Local\Temp\pwliafod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8F736202]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8F7387F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8F738848]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8F73895E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8F738746]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8F738898]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8F73879A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8F73890C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8F736226]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8F735FF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8F73624A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8F738D56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8F736CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8F738820]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8F738870]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8F738988]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8F738772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8F7388D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8F7387C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8F738936]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8F736BA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8F73626E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8F736292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8F73604A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8F736186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8F736162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8F7361AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8F7362B6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8E3AA398]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!KeInsertQueue + 2FD 824AE8F4 4 Bytes [02, 62, 73, 8F]
.text ntoskrnl.exe!KeInsertQueue + 3C1 824AE9B8 8 Bytes [F0, 87, 73, 8F, 48, 88, 73, ...] {LOCK XCHG [EBX-0x71], ESI; DEC EAX; MOV [EBX-0x71], DH}
.text ntoskrnl.exe!KeInsertQueue + 3CD 824AE9C4 4 Bytes [5E, 89, 73, 8F] {POP ESI; MOV [EBX-0x71], ESI}
.text ntoskrnl.exe!KeInsertQueue + 3E5 824AE9DC 4 Bytes [46, 87, 73, 8F] {INC ESI; XCHG [EBX-0x71], ESI}
.text ntoskrnl.exe!KeInsertQueue + 405 824AE9FC 8 Bytes [98, 88, 73, 8F, 9A, 87, 73, ...]
.text ...
PAGE ntoskrnl.exe!ObMakeTemporaryObject 825E4E46 5 Bytes JMP 8E3A5D4C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 110 8262E54F 4 Bytes CALL 8F73734B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ObInsertObject 82632A1C 5 Bytes JMP 8E3A77F2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwAlpcSendWaitReceivePort + 121 8265C013 4 Bytes CALL 8F737361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 826C9E84 7 Bytes JMP 8E3AA39C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? System32\drivers\jqbdgmq.sys Systém nemůže nalézt uvedenou cestu. !
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8D407340, 0x3EE1D7, 0xE8000020]
.text win32k.sys!EngCreateRectRgn + 4537 9981FC80 5 Bytes JMP 8F739440 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreatePalette + C20 99838EA9 5 Bytes JMP 8F739E0C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 4A1 99839C95 5 Bytes JMP 8F739F72 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 8C03 998423F7 5 Bytes JMP 8F738D8C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 616 9984334E 5 Bytes JMP 8F739BD8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 3103 9984EA94 5 Bytes JMP 8F739316 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 456E 9984FEFF 5 Bytes JMP 8F738F34 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 119C6 99869A35 5 Bytes JMP 8F739180 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 11A1A 99869A89 5 Bytes JMP 8F739326 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 377F 99890A8E 5 Bytes JMP 8F739B64 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 60DE 998933ED 5 Bytes JMP 8F738E58 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 4D3F 99899D2E 5 Bytes JMP 8F738FA4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 2B42 998A41CC 5 Bytes JMP 8F73A014 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStrokePath + 5FF 998A70B4 5 Bytes JMP 8F738E70 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 81C 998C54E5 5 Bytes JMP 8F739D54 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 6EEA 998CBBB3 5 Bytes JMP 8F739BAE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCopyBits + B0F 998CF32A 5 Bytes JMP 8F739CA2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_vEnumStart + 4728 998D6C49 5 Bytes JMP 8F738EF0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + E80 998F51BC 5 Bytes JMP 8F7390AE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_bEnum + 248 998FAA3A 5 Bytes JMP 8F739008 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 26D9 998FE572 5 Bytes JMP 8F739ECA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + A0F 9991CA97 5 Bytes JMP 8F73903E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + D269 999292F1 5 Bytes JMP 8F7390E8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF 9EC5B03F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 9EC5B0AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 9EC5B0AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 9EC5B130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 9EC5B137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
? C:\Windows\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !
? C:\Users\Honza\AppData\Local\Temp\catchme.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\System32\spoolsv.exe[232] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\spoolsv.exe[232] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\spoolsv.exe[232] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Windows\System32\spoolsv.exe[232] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000801F8
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00930600
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00930804
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00930A08
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 009301F8
.text C:\Windows\System32\spoolsv.exe[232] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 009303FC
.text C:\Windows\system32\svchost.exe[448] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[448] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[448] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[448] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[448] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00200600
.text C:\Windows\system32\svchost.exe[448] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00200804
.text C:\Windows\system32\svchost.exe[448] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00200A08
.text C:\Windows\system32\svchost.exe[448] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 002001F8
.text C:\Windows\system32\svchost.exe[448] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 002003FC
.text C:\Windows\system32\csrss.exe[624] KERNEL32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[676] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[676] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[676] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[676] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[676] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[676] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[676] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[676] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[676] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[688] KERNEL32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\services.exe[720] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[720] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[720] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[720] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[720] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[720] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[720] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[720] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[720] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\lsass.exe[732] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00080600
.text C:\Windows\system32\lsass.exe[732] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\lsass.exe[732] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\lsass.exe[732] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\lsass.exe[732] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsm.exe[740] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[740] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[740] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsm.exe[740] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 001C01F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 001C03FC
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!RegOpenKeyExA 75CD7C42 5 Bytes JMP 00043EEE C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Windows Live Family Safety Service/Microsoft Corporation)
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 001E03FC
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 001E0600
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 001E1014
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 001E0804
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 001E0A08
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 001E0C0C
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 001E0E10
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 001E01F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 001F0600
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 001F0804
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 001F0A08
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001F01F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[788] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001F03FC
.text C:\Windows\system32\winlogon.exe[816] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[816] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[816] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 001503FC
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00150600
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00151014
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00150804
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00150A08
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00150C0C
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00150E10
.text C:\Windows\system32\winlogon.exe[816] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 001501F8
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00160600
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00160804
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWindowsHookEx 761598DB 3 Bytes JMP 00160A08
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWindowsHookEx + 4 761598DF 1 Byte [8A]
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001601F8
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWinEvent 7615C06F 3 Bytes JMP 001603FC
.text C:\Windows\system32\winlogon.exe[816] USER32.dll!UnhookWinEvent + 4 7615C073 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[928] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[928] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00390600
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00390804
.text C:\Windows\system32\svchost.exe[928] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00390A08
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 003901F8
.text C:\Windows\system32\svchost.exe[928] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 003903FC
.text C:\Windows\system32\nvvsvc.exe[984] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\nvvsvc.exe[984] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 001503FC
.text C:\Windows\system32\nvvsvc.exe[984] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00170600
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00170804
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00170A08
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001701F8
.text C:\Windows\system32\nvvsvc.exe[984] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001703FC
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 001803FC
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00180600
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00181014
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00180804
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00180A08
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00180C0C
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00180E10
.text C:\Windows\system32\nvvsvc.exe[984] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1012] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1012] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1012] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00120600
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00120804
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00120A08
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001201F8
.text C:\Windows\system32\svchost.exe[1012] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001203FC
.text C:\Windows\System32\svchost.exe[1048] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1048] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1048] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00AB0600
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00AB0804
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00AB0A08
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 00AB01F8
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 00AB03FC
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00140600
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00140804
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00140A08
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001401F8
.text C:\Windows\System32\svchost.exe[1132] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001403FC
.text C:\Windows\System32\svchost.exe[1160] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1160] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1160] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Windows\System32\svchost.exe[1160] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000801F8
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00E80600
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00E80804
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00E80A08
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 00E801F8
.text C:\Windows\System32\svchost.exe[1160] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 00E803FC
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1172] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1172] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00180600
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00180804
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\AUDIODG.EXE[1296] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1316] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1316] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1316] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1316] ADVAPI32.dll!CreateServiceA 75D272A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 000E0600
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 000E0804
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 000E0A08
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000E01F8
.text C:\Windows\system32\svchost.exe[1316] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000E03FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ntdll.dll!LdrLoadDll 774093A8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ntdll.dll!LdrUnloadDll 7741B740 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] kernel32.dll!GetBinaryTypeW + 70 75F42467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!SetWindowsHookExA 76156322 5 Bytes JMP 00070600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!SetWindowsHookExW 761587AD 5 Bytes JMP 00070804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!UnhookWindowsHookEx 761598DB 5 Bytes JMP 00070A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!SetWinEventHook 76159F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] USER32.dll!UnhookWinEvent 7615C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!CreateServiceW 75CE9EB4 5 Bytes JMP 000803FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!DeleteService 75CEA07E 5 Bytes JMP 00080600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!SetServiceObjectSecurity 75D26CD9 5 Bytes JMP 00081014
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfigA 75D26DD9 5 Bytes JMP 00080804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfigW 75D26F81 5 Bytes JMP 00080A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfig2A 75D27099 5 Bytes JMP 00080C0C
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!ChangeServiceConfig2W 75D271E1 5 Bytes JMP 00080E10
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1396] ADVAPI32.dll!CreateServiceA