GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-11-29 22:25:04
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD80 rev.04.0
Running: gmer.exe; Driver: C:\DOCUME~1\Jirka\LOCALS~1\Temp\pxrdapob.sys
---- System - GMER 1.0.15 ----
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF7AF6E52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF7AD7CDE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF7AD7ED0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF7AF7640]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF7AF78F4]
SSDT spse.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spse.sys ZwEnumerateValueKey [0xF74FD132]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF7AF5B44]
SSDT spse.sys ZwQueryKey [0xF74FD20A]
SSDT spse.sys ZwQueryValueKey [0xF74FD08A]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF7AF7D60]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF7AF7112]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF7AD7984]
INT 0x62 ? 8A3BFBF8
INT 0x63 ? 89777BF8
INT 0x63 ? 89777BF8
INT 0x63 ? 89777BF8
INT 0x73 ? 89777BF8
INT 0x82 ? 8A3BFBF8
INT 0x94 ? 89777BF8
INT 0xA4 ? 89777BF8
INT 0xB4 ? 8A348BF8
---- Kernel code sections - GMER 1.0.15 ----
? spse.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B89FE8AC 5 Bytes JMP 897771D8
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\hkcmd.exe[416] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003C5840
.text C:\WINDOWS\system32\hkcmd.exe[416] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003C59E0
.text C:\WINDOWS\system32\hkcmd.exe[416] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003C6130
.text C:\WINDOWS\system32\hkcmd.exe[416] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003C5AB0
.text C:\WINDOWS\system32\hkcmd.exe[416] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003C5910
.text C:\WINDOWS\system32\hkcmd.exe[416] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003C56D8
.text C:\WINDOWS\system32\hkcmd.exe[416] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003C5C50
.text C:\WINDOWS\system32\hkcmd.exe[416] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003C5B80
.text C:\WINDOWS\system32\hkcmd.exe[416] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003C5D20
.text C:\WINDOWS\system32\hkcmd.exe[416] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003C62D0
.text C:\WINDOWS\system32\hkcmd.exe[416] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003C5F90
.text C:\WINDOWS\system32\hkcmd.exe[416] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003C6060
.text C:\WINDOWS\system32\hkcmd.exe[416] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003C6200
.text C:\WINDOWS\system32\hkcmd.exe[416] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003C5DF0
.text C:\WINDOWS\system32\hkcmd.exe[416] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003C5EC0
.text C:\WINDOWS\system32\igfxpers.exe[444] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003B57A8
.text C:\WINDOWS\system32\igfxpers.exe[444] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003B5948
.text C:\WINDOWS\system32\igfxpers.exe[444] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003B6098
.text C:\WINDOWS\system32\igfxpers.exe[444] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003B5A18
.text C:\WINDOWS\system32\igfxpers.exe[444] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003B5878
.text C:\WINDOWS\system32\igfxpers.exe[444] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003B56D8
.text C:\WINDOWS\system32\igfxpers.exe[444] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003B5BB8
.text C:\WINDOWS\system32\igfxpers.exe[444] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003B5AE8
.text C:\WINDOWS\system32\igfxpers.exe[444] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003B5C88
.text C:\WINDOWS\system32\igfxpers.exe[444] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003B6238
.text C:\WINDOWS\system32\igfxpers.exe[444] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003B5EF8
.text C:\WINDOWS\system32\igfxpers.exe[444] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003B5FC8
.text C:\WINDOWS\system32\igfxpers.exe[444] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003B6168
.text C:\WINDOWS\system32\igfxpers.exe[444] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003B5D58
.text C:\WINDOWS\system32\igfxpers.exe[444] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003B5E28
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 009F57A8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 009F5948
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 009F6098
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 009F5A18
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 009F5878
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009F5528
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009F5BB8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009F5AE8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009F5C88
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 009F6238
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 009F5EF8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 009F5FC8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 009F6168
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 009F5D58
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[456] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 009F5E28
.text C:\WINDOWS\system32\rundll32.exe[460] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003C5870
.text C:\WINDOWS\system32\rundll32.exe[460] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003C5A10
.text C:\WINDOWS\system32\rundll32.exe[460] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003C6160
.text C:\WINDOWS\system32\rundll32.exe[460] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003C5AE0
.text C:\WINDOWS\system32\rundll32.exe[460] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003C5940
.text C:\WINDOWS\system32\rundll32.exe[460] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003C5708
.text C:\WINDOWS\system32\rundll32.exe[460] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003C5C80
.text C:\WINDOWS\system32\rundll32.exe[460] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003C5BB0
.text C:\WINDOWS\system32\rundll32.exe[460] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003C5D50
.text C:\WINDOWS\system32\rundll32.exe[460] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003C6300
.text C:\WINDOWS\system32\rundll32.exe[460] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003C5FC0
.text C:\WINDOWS\system32\rundll32.exe[460] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003C6090
.text C:\WINDOWS\system32\rundll32.exe[460] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003C6230
.text C:\WINDOWS\system32\rundll32.exe[460] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003C5E20
.text C:\WINDOWS\system32\rundll32.exe[460] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003C5EF0
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003B5868
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003B5A08
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003B6158
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003B5AD8
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003B5938
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003B5700
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003B5C78
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003B5BA8
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003B5D48
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003B62F8
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003B5FB8
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003B6088
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003B6228
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003B5E18
.text C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe[472] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003B5EE8
.text c:\bbbb\gmer.exe[524] ntdll.dll!NtSetInformationThread 7C90DCAE 5 Bytes JMP 003D5660
.text c:\bbbb\gmer.exe[524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D5750
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003C5868
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003C5A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003C6158
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003C5AD8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003C5938
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003C5700
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003C5C78
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003C5BA8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003C5D48
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003C62F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003C5FB8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003C6088
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003C6228
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003C5E18
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[632] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003C5EE8
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003E5850
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003E59F0
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003E6140
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003E5AC0
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003E5920
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003E5708
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003E5C60
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003E5B90
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003E5D30
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003E62E0
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003E5FA0
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003E6070
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003E6210
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003E5E00
.text C:\Program Files\Microsoft Security Essentials\msseces.exe[696] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003E5ED0
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003B5820
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003B59C0
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003B6110
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003B5A90
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003B58F0
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003B5700
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003B5C30
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003B5B60
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003B5D00
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003B62B0
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003B5F70
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003B6040
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003B61E0
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003B5DD0
.text C:\Program Files\Rising\AntiSpyware\rstray.exe[748] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003B5EA0
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003B57B8
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003B5958
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003B60A8
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003B5A28
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003B5888
.text C:\WINDOWS\system32\igfxsrvc.exe[752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003B56E8
.text C:\WINDOWS\system32\igfxsrvc.exe[752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003B5BC8
.text C:\WINDOWS\system32\igfxsrvc.exe[752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003B5AF8
.text C:\WINDOWS\system32\igfxsrvc.exe[752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003B5C98
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003B6248
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003B5F08
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003B5FD8
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003B6178
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003B5D68
.text C:\WINDOWS\system32\igfxsrvc.exe[752] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003B5E38
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003C5698
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003C5838
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003C5F88
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003C5908
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003C5768
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003C5530
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003C5AA8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003C59D8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003C5B78
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003C6128
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003C5DE8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003C5EB8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003C6058
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003C5C48
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[820] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003C5D18
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 017C5848
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 017C59E8
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 017C6138
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 017C5AB8
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 017C5918
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 017C5700
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 017C5C58
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 017C5B88
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 017C5D28
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] advapi32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 017C62D8
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] advapi32.dll!StartServiceA 77DDFB58 5 Bytes JMP 017C5F98
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] advapi32.dll!StartServiceW 77DE3E94 5 Bytes JMP 017C6068
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] advapi32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 017C6208
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] advapi32.dll!CreateServiceA 77E27211 5 Bytes JMP 017C5DF8
.text C:\Program Files\Hard Disk Sentinel\HDSentinel.exe[956] advapi32.dll!CreateServiceW 77E273A9 5 Bytes JMP 017C5EC8
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 003A56A8
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003A5848
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 003A5F98
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 003A5918
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 003A5778
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003A5540
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003A5AB8
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003A59E8
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003A5B88
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003A6138
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 003A5DF8
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 003A5EC8
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 003A6068
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 003A5C58
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1068] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003A5D28
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00485850
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 004859F0
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 00486140
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 00485AC0
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 00485920
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 004856E8
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00485C60
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00485B90
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00485D30
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 004862E0
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 00485FA0
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 00486070
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 00486210
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 00485E00
.text C:\WINDOWS\system32\wbem\unsecapp.exe[1236] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00485ED0
.text C:\WINDOWS\system32\ctfmon.exe[1264] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00375840
.text C:\WINDOWS\system32\ctfmon.exe[1264] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 003759E0
.text C:\WINDOWS\system32\ctfmon.exe[1264] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 00376130
.text C:\WINDOWS\system32\ctfmon.exe[1264] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 00375AB0
.text C:\WINDOWS\system32\ctfmon.exe[1264] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 00375910
.text C:\WINDOWS\system32\ctfmon.exe[1264] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003756D8
.text C:\WINDOWS\system32\ctfmon.exe[1264] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00375C50
.text C:\WINDOWS\system32\ctfmon.exe[1264] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00375B80
.text C:\WINDOWS\system32\ctfmon.exe[1264] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00375D20
.text C:\WINDOWS\system32\ctfmon.exe[1264] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003762D0
.text C:\WINDOWS\system32\ctfmon.exe[1264] ADVAPI32.dll!StartServiceA 77DDFB58 5 Bytes JMP 00375F90
.text C:\WINDOWS\system32\ctfmon.exe[1264] ADVAPI32.dll!StartServiceW 77DE3E94 5 Bytes JMP 00376060
.text C:\WINDOWS\system32\ctfmon.exe[1264] ADVAPI32.dll!OpenServiceA 77DE4C66 5 Bytes JMP 00376200
.text C:\WINDOWS\system32\ctfmon.exe[1264] ADVAPI32.dll!CreateServiceA 77E27211 5 Bytes JMP 00375DF0
.text C:\WINDOWS\system32\ctfmon.exe[1264] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00375EC0