GMER 1.0.15.15077 [ofqkf2wq.exe] -
http://www.gmer.netRootkit scan 2009-09-07 22:14:43
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT 88B29630 ZwAssignProcessToJobObject
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwConnectPort [0xB750A040]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateFile [0xB7506930]
SSDT \SystemRoot\system32\drivers\sbaphd.sys (Sunbelt ActiveProtection hook driver/Sunbelt Software) ZwCreateKey [0xBAE104D0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreatePort [0xB750A510]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcess [0xB7510870]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcessEx [0xB7510AA0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateSection [0xB7513FD0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateWaitablePort [0xB750A600]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteFile [0xB7506F20]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteKey [0xB75126E0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteValueKey [0xB7512440]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDuplicateObject [0xB7510580]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwLoadKey [0xB75128B0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwMapViewOfSection [0xB7514270]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenFile [0xB7506D70]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwOpenKey [0xBA91CF68]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenProcess [0xB7510350]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenThread [0xB7510150]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRenameKey [0xB7513250]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwReplaceKey [0xB7512CB0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRequestWaitReplyPort [0xB7509C00]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRestoreKey [0xB7513080]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSecureConnectPort [0xB750A220]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetInformationFile [0xB7507120]
SSDT \SystemRoot\system32\drivers\sbaphd.sys (Sunbelt ActiveProtection hook driver/Sunbelt Software) ZwSetValueKey [0xBAE10520]
SSDT 88B29460 ZwSuspendProcess
SSDT 88B29280 ZwSuspendThread
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwTerminateProcess [0xB7510CD0]
SSDT 88B290B0 ZwTerminateThread
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C7C 80504518 12 Bytes [10, A5, 50, B7, 70, 08, 51, ...] {ADC [EBP+0x870b750], AH; PUSH ECX; MOV BH, 0xa0; OR DL, [ECX-0x49]}
? srescan.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\369.tmp The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ntdll.dll!NtLoadDriver 7C90D46E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ntdll.dll!NtLoadDriver + 4 7C90D472 2 Bytes [4A, 5F] {DEC EDX; POP EDI}
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [38, 5F]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 5FBE0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 5F880F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 5F940F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 5F100F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F220F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F1F0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!TlsGetValue 7C8097E0 6 Bytes JMP 5FB50F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 5F910F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 5FA60F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 5F580F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 5F5E0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateRemoteThread 7C8104CC 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateRemoteThread + 4 7C8104D0 2 Bytes [05, 5F]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 5F8E0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 5F850F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 5FC70F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!TerminateThread 7C81CB3B 6 Bytes JMP 5F3A0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 5FC10F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 5F5B0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5FB20F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 5FA90F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 5FAC0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateDirectoryW 7C832402 6 Bytes JMP 5FC40F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!DebugActiveProcess 7C85B0FB 6 Bytes JMP 5F3D0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CopyFileExA 7C85F39C 6 Bytes JMP 5FAF0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!WinExec 7C86250D 6 Bytes JMP 5F310F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!SetThreadContext 7C863C09 6 Bytes JMP 5FCA0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] kernel32.dll!CreateToolhelp32Snapshot 7C865C7F 6 Bytes JMP 5F8B0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F700F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F820F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F640F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F6D0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F6A0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F7F0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegSetValueExW 77DDD767 6 Bytes JMP 5F760F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegQueryValueW 77DDD87A 6 Bytes JMP 5F7C0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 6 Bytes JMP 5F610F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegSetValueExA 77DDEAE7 6 Bytes JMP 5F730F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 6 Bytes JMP 5F670F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!OpenSCManagerW 77DE6F55 6 Bytes JMP 5F9A0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!OpenSCManagerA 77DF69AE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!OpenSCManagerA + 4 77DF69B2 2 Bytes [98, 5F] {CWDE ; POP EDI}
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!RegQueryValueA 77DFBB8D 6 Bytes JMP 5F790F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!LsaRemoveAccountRights 77E1AC91 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F4C0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F4F0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!GetKeyState 7E429ED9 6 Bytes JMP 5F400F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!GetWindowTextW 7E42A5CD 6 Bytes JMP 5FA00F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!GetAsyncKeyState 7E42A78F 6 Bytes JMP 5F430F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!ShowWindow 7E42AF56 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!ShowWindow + 4 7E42AF5A 2 Bytes [A4, 5F] {MOVSB ; POP EDI}
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!SetWinEventHook 7E4317F7 6 Bytes JMP 5F520F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!GetWindowTextA 7E43216B 6 Bytes JMP 5F9D0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!DdeConnect 7E4581C3 6 Bytes JMP 5F460F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!EndTask 7E45A0A5 6 Bytes JMP 5F340F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] USER32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] SHELL32.dll!ShellExecuteExW 7CA0996B 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] SHELL32.dll!Shell_NotifyIcon 7CA28C56 6 Bytes JMP 5FB80F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 6 Bytes JMP 5FBB0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] SHELL32.dll!ShellExecuteEx 7CA40EB5 6 Bytes JMP 5F2B0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] SHELL32.dll!ShellExecuteA 7CA411E0 6 Bytes JMP 5F250F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] SHELL32.dll!ShellExecuteW 7CAB5D48 6 Bytes JMP 5F280F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] WS2_32.dll!socket 71AB4211 6 Bytes JMP 5FCD0F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] WS2_32.dll!bind 71AB4480 6 Bytes JMP 5FD00F5A
.text C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe[408] WS2_32.dll!listen 71AB8CD3 6 Bytes JMP 5FD30F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ntdll.dll!NtLoadDriver 7C90D46E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ntdll.dll!NtLoadDriver + 4 7C90D472 2 Bytes [4A, 5F] {DEC EDX; POP EDI}
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [38, 5F]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 5FBE0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 5F880F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 5F940F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 5F130F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 5F100F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F220F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F1F0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!TlsGetValue 7C8097E0 6 Bytes JMP 5FB50F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 5F910F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 5FA60F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 5F580F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 5F160F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 5F5E0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateRemoteThread 7C8104CC 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateRemoteThread + 4 7C8104D0 2 Bytes [05, 5F]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 5F8E0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 5F850F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 5FC70F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!TerminateThread 7C81CB3B 6 Bytes JMP 5F3A0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 5FC10F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 5F5B0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5FB20F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 5FA90F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 5FAC0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateDirectoryW 7C832402 6 Bytes JMP 5FC40F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!DebugActiveProcess 7C85B0FB 6 Bytes JMP 5F3D0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CopyFileExA 7C85F39C 6 Bytes JMP 5FAF0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!WinExec 7C86250D 6 Bytes JMP 5F310F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!SetThreadContext 7C863C09 6 Bytes JMP 5FCA0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] kernel32.dll!CreateToolhelp32Snapshot 7C865C7F 6 Bytes JMP 5F8B0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!GetKeyState 7E429ED9 6 Bytes JMP 5F400F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!GetWindowTextW 7E42A5CD 6 Bytes JMP 5FA00F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!GetAsyncKeyState 7E42A78F 6 Bytes JMP 5F430F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!ShowWindow 7E42AF56 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!ShowWindow + 4 7E42AF5A 2 Bytes [A4, 5F] {MOVSB ; POP EDI}
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F190F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!SetWinEventHook 7E4317F7 6 Bytes JMP 5F520F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!GetWindowTextA 7E43216B 6 Bytes JMP 5F9D0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!DdeConnect 7E4581C3 6 Bytes JMP 5F460F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!EndTask 7E45A0A5 6 Bytes JMP 5F340F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] USER32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F700F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F820F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F640F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F6D0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F6A0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F7F0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegSetValueExW 77DDD767 6 Bytes JMP 5F760F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegQueryValueW 77DDD87A 6 Bytes JMP 5F7C0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 6 Bytes JMP 5F610F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegSetValueExA 77DDEAE7 6 Bytes JMP 5F730F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 6 Bytes JMP 5F670F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!OpenSCManagerW 77DE6F55 6 Bytes JMP 5F9A0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!OpenSCManagerA 77DF69AE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!OpenSCManagerA + 4 77DF69B2 2 Bytes [98, 5F] {CWDE ; POP EDI}
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!RegQueryValueA 77DFBB8D 6 Bytes JMP 5F790F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!LsaRemoveAccountRights 77E1AC91 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F4C0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F4F0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] SHELL32.dll!ShellExecuteExW 7CA0996B 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] SHELL32.dll!Shell_NotifyIcon 7CA28C56 6 Bytes JMP 5FB80F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 6 Bytes JMP 5FBB0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] SHELL32.dll!ShellExecuteEx 7CA40EB5 6 Bytes JMP 5F2B0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] SHELL32.dll!ShellExecuteA 7CA411E0 6 Bytes JMP 5F250F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] SHELL32.dll!ShellExecuteW 7CAB5D48 6 Bytes JMP 5F280F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] WS2_32.dll!socket 71AB4211 6 Bytes JMP 5FCD0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] WS2_32.dll!bind 71AB4480 6 Bytes JMP 5FD00F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[560] WS2_32.dll!listen 71AB8CD3 6 Bytes JMP 5FD30F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ntdll.dll!NtLoadDriver 7C90D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\DllHost.exe[672] ntdll.dll!NtLoadDriver + 4 7C90D472 2 Bytes [4A, 5F] {DEC EDX; POP EDI}
.text C:\WINDOWS\system32\DllHost.exe[672] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\DllHost.exe[672] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [38, 5F]
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 5FBE0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!TlsGetValue 7C8097E0 6 Bytes JMP 5FB50F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 5F5E0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateRemoteThread 7C8104CC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateRemoteThread + 4 7C8104D0 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 5FC70F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!TerminateThread 7C81CB3B 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 5FC10F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5FB20F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 5FAC0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateDirectoryW 7C832402 6 Bytes JMP 5FC40F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!DebugActiveProcess 7C85B0FB 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CopyFileExA 7C85F39C 6 Bytes JMP 5FAF0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!WinExec 7C86250D 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!SetThreadContext 7C863C09 6 Bytes JMP 5FCA0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] kernel32.dll!CreateToolhelp32Snapshot 7C865C7F 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegSetValueExW 77DDD767 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegQueryValueW 77DDD87A 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegSetValueExA 77DDEAE7 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!OpenSCManagerW 77DE6F55 6 Bytes JMP 5F9A0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!OpenSCManagerA 77DF69AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!OpenSCManagerA + 4 77DF69B2 2 Bytes [98, 5F] {CWDE ; POP EDI}
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!RegQueryValueA 77DFBB8D 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!LsaRemoveAccountRights 77E1AC91 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!GetKeyState 7E429ED9 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!GetWindowTextW 7E42A5CD 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!GetAsyncKeyState 7E42A78F 6 Bytes JMP 5F430F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!ShowWindow 7E42AF56 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!ShowWindow + 4 7E42AF5A 2 Bytes [A4, 5F] {MOVSB ; POP EDI}
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!SetWinEventHook 7E4317F7 6 Bytes JMP 5F520F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!GetWindowTextA 7E43216B 6 Bytes JMP 5F9D0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!DdeConnect 7E4581C3 6 Bytes JMP 5F460F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!EndTask 7E45A0A5 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\DllHost.exe[672] USER32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\WINDOWS\system32\DllHost.exe[672] SHELL32.dll!ShellExecuteExW 7CA0996B 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] SHELL32.dll!Shell_NotifyIcon 7CA28C56 6 Bytes JMP 5FB80F5A
.text C:\WINDOWS\system32\DllHost.exe[672] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 6 Bytes JMP 5FBB0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] SHELL32.dll!ShellExecuteEx 7CA40EB5 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] SHELL32.dll!ShellExecuteA 7CA411E0 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\DllHost.exe[672] SHELL32.dll!ShellExecuteW 7CAB5D48 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\DllHost.exe[672] WS2_32.dll!socket 71AB4211 6 Bytes JMP 5FCD0F5A
.text C:\WINDOWS\system32\DllHost.exe[672] WS2_32.dll!bind 71AB4480 6 Bytes JMP 5FD00F5A
.text C:\WINDOWS\system32\DllHost.exe[672] WS2_32.dll!listen 71AB8CD3 6 Bytes JMP 5FD30F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 5F430F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!TlsGetValue 7C8097E0 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 5F550F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CreateDirectoryW 7C832402 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CopyFileExA 7C85F39C 6 Bytes JMP 5F5E0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!SetThreadContext 7C863C09 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\winlogon.exe[772] kernel32.dll!CreateToolhelp32Snapshot 7C865C7F 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegSetValueExW 77DDD767 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegQueryValueW 77DDD87A 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegSetValueExA 77DDEAE7 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!OpenSCManagerW 77DE6F55 6 Bytes JMP 5F490F5A
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!OpenSCManagerA 77DF69AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!OpenSCManagerA + 4 77DF69B2 2 Bytes [47, 5F] {INC EDI; POP EDI}
.text C:\WINDOWS\system32\winlogon.exe[772] ADVAPI32.dll!RegQueryValueA 77DFBB8D 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\winlogon.exe[772] USER32.dll!GetWindowTextW 7E42A5CD 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] USER32.dll!ShowWindow 7E42AF56 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\winlogon.exe[772] USER32.dll!ShowWindow + 4 7E42AF5A 2 Bytes [53, 5F] {PUSH EBX; POP EDI}
.text C:\WINDOWS\system32\winlogon.exe[772] USER32.dll!GetWindowTextA 7E43216B 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] WS2_32.dll!socket 71AB4211 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] WS2_32.dll!bind 71AB4480 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\winlogon.exe[772] WS2_32.dll!listen 71AB8CD3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\winlogon.exe[772] SHELL32.dll!Shell_NotifyIcon 7CA28C56 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\winlogon.exe[772] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\services.exe[820] ntdll.dll!NtLoadDriver 7C90D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[820] ntdll.dll!NtLoadDriver + 4 7C90D472 2 Bytes [4A, 5F] {DEC EDX; POP EDI}
.text C:\WINDOWS\system32\services.exe[820] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[820] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [38, 5F]
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 5FBF0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 5F890F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 5F950F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!TlsGetValue 7C8097E0 6 Bytes JMP 5FB60F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 5F920F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 5FA70F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 5F5E0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateRemoteThread 7C8104CC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateRemoteThread + 4 7C8104D0 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 5F8F0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 5F860F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 5FC80F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!TerminateThread 7C81CB3B 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 5FC20F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5FB30F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 5FAA0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 5FAD0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateDirectoryW 7C832402 6 Bytes JMP 5FC50F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!DebugActiveProcess 7C85B0FB 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CopyFileExA 7C85F39C 6 Bytes JMP 5FB00F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!WinExec 7C86250D 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!SetThreadContext 7C863C09 6 Bytes JMP 5FCB0F5A
.text C:\WINDOWS\system32\services.exe[820] kernel32.dll!CreateToolhelp32Snapshot 7C865C7F 6 Bytes JMP 5F8C0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F830F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F800F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegSetValueExW 77DDD767 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegQueryValueW 77DDD87A 6 Bytes JMP 5F7D0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegSetValueExA 77DDEAE7 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!OpenSCManagerW 77DE6F55 6 Bytes JMP 5F9B0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!OpenSCManagerA 77DF69AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!OpenSCManagerA + 4 77DF69B2 2 Bytes [99, 5F] {CDQ ; POP EDI}
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!RegQueryValueA 77DFBB8D 6 Bytes JMP 5F7A0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!LsaRemoveAccountRights 77E1AC91 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!GetKeyState 7E429ED9 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!GetWindowTextW 7E42A5CD 6 Bytes JMP 5FA10F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!GetAsyncKeyState 7E42A78F 6 Bytes JMP 5F430F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!ShowWindow 7E42AF56 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!ShowWindow + 4 7E42AF5A 2 Bytes [A5, 5F] {MOVSD ; POP EDI}
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!SetWinEventHook 7E4317F7 6 Bytes JMP 5F520F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!GetWindowTextA 7E43216B 6 Bytes JMP 5F9E0F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!DdeConnect 7E4581C3 6 Bytes JMP 5F460F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!EndTask 7E45A0A5 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[820] USER32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\WINDOWS\system32\services.exe[820] WS2_32.dll!socket 71AB4211 6 Bytes JMP 5FCE0F5A
.text C:\WINDOWS\system32\services.exe[820] WS2_32.dll!bind 71AB4480 6 Bytes JMP 5FD10F5A
.text C:\WINDOWS\system32\services.exe[820] WS2_32.dll!listen 71AB8CD3 6 Bytes JMP 5FD40F5A
.text C:\WINDOWS\system32\services.exe[820] SHELL32.dll!ShellExecuteExW 7CA0996B 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\services.exe[820] SHELL32.dll!Shell_NotifyIcon 7CA28C56 6 Bytes JMP 5FB90F5A
.text C:\WINDOWS\system32\services.exe[820] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 6 Bytes JMP 5FBC0F5A
.text C:\WINDOWS\system32\services.exe[820] SHELL32.dll!ShellExecuteEx 7CA40EB5 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\services.exe[820] SHELL32.dll!ShellExecuteA 7CA411E0 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\services.exe[820] SHELL32.dll!ShellExecuteW 7CAB5D48 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!NtLoadDriver 7C90D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!NtLoadDriver + 4 7C90D472 2 Bytes [4A, 5F] {DEC EDX; POP EDI}
.text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [38, 5F]
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 5FBE0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!TlsGetValue 7C8097E0 6 Bytes JMP 5FB50F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 5F5E0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateRemoteThread 7C8104CC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateRemoteThread + 4 7C8104D0 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 5FC70F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!TerminateThread 7C81CB3B 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 5FC10F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5FB20F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 5FAC0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateDirectoryW 7C832402 6 Bytes JMP 5FC40F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!DebugActiveProcess 7C85B0FB 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CopyFileExA 7C85F39C 6 Bytes JMP 5FAF0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!WinExec 7C86250D 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!SetThreadContext 7C863C09 6 Bytes JMP 5FCA0F5A
.text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!CreateToolhelp32Snapshot 7C865C7F 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegSetValueExW 77DDD767 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegQueryValueW 77DDD87A 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegSetValueExA 77DDEAE7 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!OpenSCManagerW 77DE6F55 6 Bytes JMP 5F9A0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!OpenSCManagerA 77DF69AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!OpenSCManagerA + 4 77DF69B2 2 Bytes [98, 5F] {CWDE ; POP EDI}
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!RegQueryValueA 77DFBB8D 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!LsaRemoveAccountRights 77E1AC91 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!GetKeyState 7E429ED9 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!GetWindowTextW 7E42A5CD 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!GetAsyncKeyState 7E42A78F 6 Bytes JMP 5F430F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!ShowWindow 7E42AF56 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!ShowWindow + 4 7E42AF5A 2 Bytes [A4, 5F] {MOVSB ; POP EDI}
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!SetWinEventHook 7E4317F7 6 Bytes JMP 5F520F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!GetWindowTextA 7E43216B 6 Bytes JMP 5F9D0F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!DdeConnect 7E4581C3 6 Bytes JMP 5F460F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!EndTask 7E45A0A5 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\WINDOWS\system32\lsass.exe[832] WS2_32.dll!socket 71AB4211 6 Bytes JMP 5FCD0F5A
.text C:\WINDOWS\system32\lsass.exe[832] WS2_32.dll!bind 71AB4480 6 Bytes JMP 5FD00F5A
.text C:\WINDOWS\system32\lsass.exe[832] WS2_32.dll!listen 71AB8CD3 6 Bytes JMP 5FD30F5A
.text C:\WINDOWS\system32\lsass.exe[832] SHELL32.dll!ShellExecuteExW 7CA0996B 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\lsass.exe[832] SHELL32.dll!Shell_NotifyIcon 7CA28C56 6 Bytes JMP 5FB80F5A
.text C:\WINDOWS\system32\lsass.exe[832] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 6 Bytes JMP 5FBB0F5A
.text C:\WINDOWS\system32\lsass.exe[832] SHELL32.dll!ShellExecuteEx 7CA40EB5 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\lsass.exe[832] SHELL32.dll!ShellExecuteA 7CA411E0 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\lsass.exe[832] SHELL32.dll!ShellExecuteW 7CAB5D48 6 Bytes JMP 5F280F5A