Ještě GMER Déčka
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-09-05 00:29:53
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0000
Running: gmer.exe; Driver: C:\Users\Honza\AppData\Local\Temp\pwliafod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8E730202]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8E7327F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8E732848]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8E73295E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8E732746]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8E732898]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8E73279A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8E73290C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8E730226]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8E72FFF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8E73024A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8E732D56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8E730CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8E732820]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8E732870]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8E732988]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8E732772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8E7328D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8E7327C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8E732936]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8E730BA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8E73026E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8E730292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8E73004A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8E730186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8E730162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8E7301AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8E7302B6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8D798398]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!KeInsertQueue + 2FD 824B88F4 4 Bytes [02, 02, 73, 8E] {ADD AL, [EDX]; JAE 0xffffffffffffff92}
.text ntoskrnl.exe!KeInsertQueue + 3C1 824B89B8 8 Bytes [F0, 27, 73, 8E, 48, 28, 73, ...]
.text ntoskrnl.exe!KeInsertQueue + 3CD 824B89C4 4 Bytes [5E, 29, 73, 8E] {POP ESI; SUB [EBX-0x72], ESI}
.text ntoskrnl.exe!KeInsertQueue + 3E5 824B89DC 4 Bytes [46, 27, 73, 8E] {INC ESI; DAA ; JAE 0xffffffffffffff92}
.text ntoskrnl.exe!KeInsertQueue + 405 824B89FC 8 Bytes [98, 28, 73, 8E, 9A, 27, 73, ...]
.text ...
PAGE ntoskrnl.exe!ObMakeTemporaryObject 825EEE46 5 Bytes JMP 8D793D4C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 110 8263854F 4 Bytes CALL 8E73134B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ObInsertObject 8263CA1C 5 Bytes JMP 8D7957F2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwAlpcSendWaitReceivePort + 121 82666013 4 Bytes CALL 8E731361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 826D3E84 7 Bytes JMP 8D79839C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8C80E340, 0x3EE1D7, 0xE8000020]
.text win32k.sys!EngCreateRectRgn + 4537 98C9FC80 5 Bytes JMP 8E733440 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreatePalette + C20 98CB8EA9 5 Bytes JMP 8E733E0C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 4A1 98CB9C95 5 Bytes JMP 8E733F72 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 8C03 98CC23F7 5 Bytes JMP 8E732D8C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 616 98CC334E 5 Bytes JMP 8E733BD8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 3103 98CCEA94 5 Bytes JMP 8E733316 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 456E 98CCFEFF 5 Bytes JMP 8E732F34 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 119C6 98CE9A35 5 Bytes JMP 8E733180 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 11A1A 98CE9A89 5 Bytes JMP 8E733326 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 377F 98D10A8E 5 Bytes JMP 8E733B64 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 60DE 98D133ED 5 Bytes JMP 8E732E58 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 4D3F 98D19D2E 5 Bytes JMP 8E732FA4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 2B42 98D241CC 5 Bytes JMP 8E734014 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStrokePath + 5FF 98D270B4 5 Bytes JMP 8E732E70 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 81C 98D454E5 5 Bytes JMP 8E733D54 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 6EEA 98D4BBB3 5 Bytes JMP 8E733BAE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCopyBits + B0F 98D4F32A 5 Bytes JMP 8E733CA2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_vEnumStart + 4728 98D56C49 5 Bytes JMP 8E732EF0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + E80 98D751BC 5 Bytes JMP 8E7330AE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_bEnum + 248 98D7AA3A 5 Bytes JMP 8E733008 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 26D9 98D7E572 5 Bytes JMP 8E733ECA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + A0F 98D9CA97 5 Bytes JMP 8E73303E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + D269 98DA92F1 5 Bytes JMP 8E7330E8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF 9F05A03F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 9F05A0AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 9F05A0AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 9F05A130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 9F05A137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
? C:\ComboFix\catchme.sys Systém nemůže nalézt uvedenou cestu. !
? C:\Windows\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 001401F8
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 001403FC
.text C:\Program Files\Firebird\bin\fbguard.exe[12] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Program Files\Firebird\bin\fbguard.exe[12] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00160600
.text C:\Program Files\Firebird\bin\fbguard.exe[12] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00160804
.text C:\Program Files\Firebird\bin\fbguard.exe[12] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00160A08
.text C:\Program Files\Firebird\bin\fbguard.exe[12] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 001601F8
.text C:\Program Files\Firebird\bin\fbguard.exe[12] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 001603FC
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 001703FC
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00170600
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00171014
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00170804
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00170A08
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00170C0C
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00170E10
.text C:\Program Files\Firebird\bin\fbguard.exe[12] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 001701F8
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 002401F8
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 002403FC
.text C:\Program Files\Firebird\bin\fbserver.exe[156] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Program Files\Firebird\bin\fbserver.exe[156] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00260600
.text C:\Program Files\Firebird\bin\fbserver.exe[156] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00260804
.text C:\Program Files\Firebird\bin\fbserver.exe[156] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00260A08
.text C:\Program Files\Firebird\bin\fbserver.exe[156] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 002601F8
.text C:\Program Files\Firebird\bin\fbserver.exe[156] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 002603FC
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 002703FC
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00270600
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00271014
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00270804
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00270A08
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00270C0C
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00270E10
.text C:\Program Files\Firebird\bin\fbserver.exe[156] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 002701F8
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 001501F8
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 001503FC
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 002703FC
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00270600
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00271014
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00270804
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00270A08
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00270C0C
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00270E10
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 002701F8
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00280600
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00280804
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00280A08
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 002801F8
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[304] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 002803FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00070600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00070804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00070A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00180600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00181014
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00180804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00180A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00180C0C
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00180E10
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[316] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[400] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[400] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[400] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[400] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\csrss.exe[540] KERNEL32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!RegOpenKeyExA 77257C42 5 Bytes JMP 001A3EEE C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Windows Live Family Safety Service/Microsoft Corporation)
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00080600
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00080804
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00080A08
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000801F8
.text C:\Program Files\Windows Live\Family Safety\fsssvc.exe[580] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\wininit.exe[588] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[588] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[588] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[588] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[588] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[588] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[588] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[588] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[588] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\services.exe[632] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[632] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[632] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[632] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[632] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[632] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[632] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[632] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[632] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[644] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[644] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\lsass.exe[644] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00080600
.text C:\Windows\system32\lsass.exe[644] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\lsass.exe[644] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\lsass.exe[644] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\lsass.exe[644] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000901F8
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000903FC
.text C:\Windows\system32\lsm.exe[656] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\winlogon.exe[728] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[728] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[728] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\winlogon.exe[728] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\winlogon.exe[728] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 000A0600
.text C:\Windows\system32\winlogon.exe[728] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 000A0804
.text C:\Windows\system32\winlogon.exe[728] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 000A0A08
.text C:\Windows\system32\winlogon.exe[728] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000A01F8
.text C:\Windows\system32\winlogon.exe[728] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[820] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[836] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[836] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[836] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[836] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\nvvsvc.exe[892] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\nvvsvc.exe[892] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 001503FC
.text C:\Windows\system32\nvvsvc.exe[892] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\nvvsvc.exe[892] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00180600
.text C:\Windows\system32\nvvsvc.exe[892] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00180804
.text C:\Windows\system32\nvvsvc.exe[892] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\nvvsvc.exe[892] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\nvvsvc.exe[892] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 001903FC
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00190600
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00191014
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00190804
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00190A08
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00190C0C
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00190E10
.text C:\Windows\system32\nvvsvc.exe[892] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 001901F8
.text C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00760600
.text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00760804
.text C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 00760A08
.text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 007601F8
.text C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 007603FC
.text C:\Windows\System32\svchost.exe[972] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[972] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[972] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 006A0600
.text C:\Windows\System32\svchost.exe[972] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 006A0804
.text C:\Windows\System32\svchost.exe[972] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 006A0A08
.text C:\Windows\System32\svchost.exe[972] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 006A01F8
.text C:\Windows\System32\svchost.exe[972] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 006A03FC
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[1004] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1048] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1048] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1048] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1048] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 000B0600
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 000B0804
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!UnhookWindowsHookEx 773598DB 5 Bytes JMP 000B0A08
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!SetWinEventHook 77359F3A 5 Bytes JMP 000B01F8
.text C:\Windows\System32\svchost.exe[1048] USER32.dll!UnhookWinEvent 7735C06F 5 Bytes JMP 000B03FC
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrLoadDll 77BD93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrUnloadDll 77BEB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!GetBinaryTypeW + 70 763E2467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceW 77269EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!DeleteService 7726A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetServiceObjectSecurity 772A6CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigA 772A6DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigW 772A6F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2A 772A7099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2W 772A71E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceA 772A72A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWindowsHookExA 77356322 5 Bytes JMP 00810600
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWindowsHookExW 773587AD 5 Bytes JMP 00810804
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!UnhookWindowsHookEx