I was working on other computers and noticed the same rogue that I had picked up and the Trojan.Hiloti. They however had the PUP of Whitesmoke which was very tricky to remove but I was able to research more about it which included the removal of a rootkit. I pulled my HDD and scanned it externally with Microsoft Security Essentials and it continuously picked up a rootkit that I could not repair. I used TDSS to fix the bluescreen (worked with several other computers) which removed the rootkit that was affecting the boot order, if that makes sense. SpyBot picked up more traces and MB picked up more as it updated.
McAfee is my current antivirus and I’m debating if I should uninstall it and use MSSE instead. It became corrupt and I had to go through the McAfee site to repair the software… I also uninstalled and attempted to delete all traces of google chrome (as it would not launch). I could not even import bookmarks into IE so I copied the two files associated with the bookmarks and set them aside.
Chrome now works but I have not yet replaced the bookmark files for fear that they will be corrupt.
Currently I've had my wireless connection tap out. It will run in safe and will work again on a reboot. Drivers are updated on my card and I’m fairly certain it’s not a hardware given the infection. I just want to be sure that ALL traces are removed. My computer is still slower than it should be.
Please let me know if I am not following your instructions correctly.
OTL Quickscan:
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.sys /90
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\System32\config\*.sav
%SYSTEMDRIVE%\*.*
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\*. /mp /s
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
GMER (no BSOD):
GMER 1.0.15.15530 -
http://www.gmer.netRootkit scan 2010-12-26 12:37:05
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST9160821AS rev.3.CDD
Running: gmer.exe; Driver: C:\Users\Kim\AppData\Local\Temp\pwldqpow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x890430B8]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x890430E2]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x890430CE]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x890430A4]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 83276148 5 Bytes JMP 890430A8 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 8328E599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 832B2F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[112] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 700D9A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[112] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 700D9AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\system32\services.exe[600] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00230FEF
.text C:\Windows\system32\services.exe[600] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00230025
.text C:\Windows\system32\services.exe[600] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00230000
.text C:\Windows\system32\services.exe[600] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 001C0079
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 001C00CA
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 001C00AF
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 001C0025
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 001C0068
.text C:\Windows\system32\services.exe[600] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 001C0F75
.text C:\Windows\system32\services.exe[600] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 001C0F86
.text C:\Windows\system32\services.exe[600] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 001C0F97
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 001C0FE5
.text C:\Windows\system32\services.exe[600] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 001C00DB
.text C:\Windows\system32\services.exe[600] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 001C0FB9
.text C:\Windows\system32\services.exe[600] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 001C0FA8
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 001C0000
.text C:\Windows\system32\services.exe[600] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 001C008A
.text C:\Windows\system32\services.exe[600] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 001C0FCA
.text C:\Windows\system32\services.exe[600] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 001C0F35
.text C:\Windows\system32\services.exe[600] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 001C0F64
.text C:\Windows\system32\services.exe[600] msvcrt.dll!_open 77057E48 5 Bytes JMP 00340000
.text C:\Windows\system32\services.exe[600] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00340F7C
.text C:\Windows\system32\services.exe[600] msvcrt.dll!system 7708B16F 5 Bytes JMP 00340FA1
.text C:\Windows\system32\services.exe[600] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00340FCD
.text C:\Windows\system32\services.exe[600] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00340FB2
.text C:\Windows\system32\services.exe[600] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00340011
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00320FEF
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 0032002C
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00320F9B
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 0032003D
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00320000
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00320058
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 1 Byte [E9]
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00320011
.text C:\Windows\system32\services.exe[600] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00320FC0
.text C:\Windows\system32\services.exe[600] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00330000
.text C:\Windows\system32\lsass.exe[644] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 000F0000
.text C:\Windows\system32\lsass.exe[644] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 000F0022
.text C:\Windows\system32\lsass.exe[644] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 000F0011
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 000E00CE
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 000E010B
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 000E0F80
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 000E002F
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 000E00BD
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 000E0091
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 000E0FAF
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 000E006C
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 000E0FE5
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 000E0F51
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 000E0040
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 000E0051
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 000E0000
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 000E00DF
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 000E0FD4
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 000E00FA
.text C:\Windows\system32\lsass.exe[644] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 000E00AC
.text C:\Windows\system32\lsass.exe[644] msvcrt.dll!_open 77057E48 5 Bytes JMP 00660FEF
.text C:\Windows\system32\lsass.exe[644] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00660FB2
.text C:\Windows\system32\lsass.exe[644] msvcrt.dll!system 7708B16F 5 Bytes JMP 00660FC3
.text C:\Windows\system32\lsass.exe[644] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00660029
.text C:\Windows\system32\lsass.exe[644] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00660FD4
.text C:\Windows\system32\lsass.exe[644] msvcrt.dll!_wopen 77090570 5 Bytes JMP 0066000C
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00100000
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 0010003D
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00100FA5
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00100FC0
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00100011
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00100062
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 0010002C
.text C:\Windows\system32\lsass.exe[644] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00100FD1
.text C:\Windows\system32\lsass.exe[644] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00110000
.text C:\Windows\system32\svchost.exe[776] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00460000
.text C:\Windows\system32\svchost.exe[776] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00460FD1
.text C:\Windows\system32\svchost.exe[776] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00460011
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 003600A2
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 003600DF
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 003600CE
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00360FCA
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00360091
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 0036005B
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00360F8D
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00360F9E
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00360FE5
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00360F39
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00360036
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00360FAF
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00360000
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00360F5E
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 0036001B
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 003600BD
.text C:\Windows\system32\svchost.exe[776] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 0036006C
.text C:\Windows\system32\svchost.exe[776] msvcrt.dll!_open 77057E48 5 Bytes JMP 00CB0FEF
.text C:\Windows\system32\svchost.exe[776] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00CB0FC1
.text C:\Windows\system32\svchost.exe[776] msvcrt.dll!system 7708B16F 5 Bytes JMP 00CB0042
.text C:\Windows\system32\svchost.exe[776] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00CB0027
.text C:\Windows\system32\svchost.exe[776] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00CB0FD2
.text C:\Windows\system32\svchost.exe[776] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00CB000C
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 004B0FEF
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 004B001B
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 004B0F83
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 004B0F94
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 004B0000
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 004B0040
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 004B0FD4
.text C:\Windows\system32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 004B0FAF
.text C:\Windows\system32\svchost.exe[776] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00BE0000
.text C:\Windows\system32\svchost.exe[856] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 004E0000
.text C:\Windows\system32\svchost.exe[856] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 004E001B
.text C:\Windows\system32\svchost.exe[856] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 004E0FE5
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 00280062
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00280F03
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00280098
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00280FAF
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00280F43
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00280F6F
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00280047
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00280F8A
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00280000
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00280EF2
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 0028001B
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 0028002C
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00280FE5
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00280F28
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00280FC0
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 0028007D
.text C:\Windows\system32\svchost.exe[856] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00280F54
.text C:\Windows\system32\svchost.exe[856] msvcrt.dll!_open 77057E48 5 Bytes JMP 00980FEF
.text C:\Windows\system32\svchost.exe[856] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00980F9C
.text C:\Windows\system32\svchost.exe[856] msvcrt.dll!system 7708B16F 5 Bytes JMP 00980FC1
.text C:\Windows\system32\svchost.exe[856] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00980016
.text C:\Windows\system32\svchost.exe[856] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00980031
.text C:\Windows\system32\svchost.exe[856] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00980FD2
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 007D0000
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 007D0FC7
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 007D0073
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 007D004E
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 007D0011
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 007D0084
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 007D002C
.text C:\Windows\system32\svchost.exe[856] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 007D003D
.text C:\Windows\system32\svchost.exe[856] WS2_32.dll!socket 75E43F00 5 Bytes JMP 007E000A
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00B90000
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00B90022
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00B90011
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 00B80079
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00B80EFF
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00B80094
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00B80FA8
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00B8005E
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00B80F50
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00B80028
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00B80F61
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00B80FD4
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00B80EEE
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00B80F97
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00B80F7C
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00B80FE5
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00B80F35
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00B80FB9
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00B80F1A
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00B8004D
.text C:\Windows\System32\svchost.exe[908] msvcrt.dll!_open 77057E48 5 Bytes JMP 00C40000
.text C:\Windows\System32\svchost.exe[908] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00C40047
.text C:\Windows\System32\svchost.exe[908] msvcrt.dll!system 7708B16F 5 Bytes JMP 00C4002C
.text C:\Windows\System32\svchost.exe[908] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00C40011
.text C:\Windows\System32\svchost.exe[908] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00C40FBC
.text C:\Windows\System32\svchost.exe[908] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00C40FE3
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00C20000
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00C20FB6
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00C20FA5
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00C20047
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00C20011
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00C20058
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00C20FE5
.text C:\Windows\System32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00C2002C
.text C:\Windows\System32\svchost.exe[908] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00C30000
.text C:\Windows\System32\svchost.exe[960] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00A80FEF
.text C:\Windows\System32\svchost.exe[960] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00A80014
.text C:\Windows\System32\svchost.exe[960] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00A80FDE
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 00A70F7C
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00A70F50
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00A70F61
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00A70FCA
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00A70F8D
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00A70FA8
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00A70080
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00A70065
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00A7001B
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00A700F6
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00A70FB9
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00A7004A
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00A70000
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00A700C0
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00A70FDB
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00A700DB
.text C:\Windows\System32\svchost.exe[960] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00A7009B
.text C:\Windows\System32\svchost.exe[960] msvcrt.dll!_open 77057E48 5 Bytes JMP 00B30000
.text C:\Windows\System32\svchost.exe[960] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00B3005D
.text C:\Windows\System32\svchost.exe[960] msvcrt.dll!system 7708B16F 5 Bytes JMP 00B30FC8
.text C:\Windows\System32\svchost.exe[960] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00B30038
.text C:\Windows\System32\svchost.exe[960] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00B30FD9
.text C:\Windows\System32\svchost.exe[960] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00B3001D
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00A90000
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00A90FB9
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00A90051
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00A90040
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00A90FE5
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00A90F94
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00A90025
.text C:\Windows\System32\svchost.exe[960] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00A90FCA
.text C:\Windows\System32\svchost.exe[960] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00AE0FEF
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00B40000
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00B40022
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00B40011
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 00B30F8D
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00B30F46
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00B300DB
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00B30036
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00B30F9E
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00B30091
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00B30FAF
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00B3006C
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00B30FEF
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00B30F2B
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00B30051
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00B30FCA
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00B30000
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00B30F7C
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00B3001B
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00B30F6B
.text C:\Windows\system32\svchost.exe[1004] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00B300AC
.text C:\Windows\system32\svchost.exe[1004] msvcrt.dll!_open 77057E48 5 Bytes JMP 00BF0000
.text C:\Windows\system32\svchost.exe[1004] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00BF0F81
.text C:\Windows\system32\svchost.exe[1004] msvcrt.dll!system 7708B16F 5 Bytes JMP 00BF0F9C
.text C:\Windows\system32\svchost.exe[1004] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00BF0FD2
.text C:\Windows\system32\svchost.exe[1004] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00BF0FAD
.text C:\Windows\system32\svchost.exe[1004] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00BF0FEF
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00B50FEF
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00B50FC3
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00B50054
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00B50FB2
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00B50FDE
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00B50F8D
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00B50014
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00B5002F
.text C:\Windows\system32\svchost.exe[1004] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00BE0000
.text C:\Windows\system32\svchost.exe[1108] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 0098000A
.text C:\Windows\system32\svchost.exe[1108] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00980036
.text C:\Windows\system32\svchost.exe[1108] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00980025
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 00930F2B
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00930EFF
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00930094
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00930FA5
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00930F3C
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00930F5E
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00930F6F
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 0093002C
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00930FCA
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!GetProcAddress 76071857 3 Bytes JMP 009300AF
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!GetProcAddress + 4 7607185B 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!LoadLibraryA 76072884 3 Bytes JMP 00930F8A
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!LoadLibraryA + 4 76072888 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!LoadLibraryW 760728D2 3 Bytes JMP 00930011
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!LoadLibraryW + 4 760728D6 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateFileA 7607291C 3 Bytes JMP 00930FE5
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateFileA + 4 76072920 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoW 76077CD5 3 Bytes JMP 00930F1A
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoW + 4 76077CD9 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00930000
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00930083
.text C:\Windows\system32\svchost.exe[1108] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00930F4D
.text C:\Windows\system32\svchost.exe[1108] msvcrt.dll!_open 77057E48 5 Bytes JMP 009B0FEF
.text C:\Windows\system32\svchost.exe[1108] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 009B003D
.text C:\Windows\system32\svchost.exe[1108] msvcrt.dll!system 7708B16F 5 Bytes JMP 009B0FA8
.text C:\Windows\system32\svchost.exe[1108] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 009B0018
.text C:\Windows\system32\svchost.exe[1108] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 009B0FB9
.text C:\Windows\system32\svchost.exe[1108] msvcrt.dll!_wopen 77090570 5 Bytes JMP 009B0FDE
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00990FEF
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00990036
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 0099006C
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00990051
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 0099000A
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00990FAF
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 0099001B
.text C:\Windows\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00990FCA
.text C:\Windows\system32\svchost.exe[1108] WS2_32.dll!socket 75E43F00 5 Bytes JMP 009A000A
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 002B0FEF
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 002B0FB9
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 002B0FD4
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 001A00C1
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 001A0101
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 001A0F6C
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 001A0FC0
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 001A00B0
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 001A007A
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 001A0069
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 001A0058
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 001A0011
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 001A0112
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 001A002C
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 001A0047
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 001A0000
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 001A00DC
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 001A0FDB
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 001A0F7D
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 001A0095
.text C:\Windows\system32\svchost.exe[1212] msvcrt.dll!_open 77057E48 5 Bytes JMP 00310FE3
.text C:\Windows\system32\svchost.exe[1212] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00310047
.text C:\Windows\system32\svchost.exe[1212] msvcrt.dll!system 7708B16F 5 Bytes JMP 00310FBC
.text C:\Windows\system32\svchost.exe[1212] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 0031001B
.text C:\Windows\system32\svchost.exe[1212] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 0031002C
.text C:\Windows\system32\svchost.exe[1212] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00310000
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00190000
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00190FCA
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00190062
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00190047
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00190011
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00190FAF
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00190FDB
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 0019002C
.text C:\Windows\system32\svchost.exe[1212] WS2_32.dll!socket 75E43F00 5 Bytes JMP 002C0FEF
.text C:\Windows\system32\svchost.exe[1356] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00A10FEF
.text C:\Windows\system32\svchost.exe[1356] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00A10025
.text C:\Windows\system32\svchost.exe[1356] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00A10014
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 009C0F3C
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 009C00AC
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 009C009B
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 009C0FB9
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 009C0F4D
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 009C005B
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 009C004A
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 009C0F8D
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 009C0FEF
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 009C00C7
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 009C0F9E
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 009C0025
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 009C0000
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 009C0F2B
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 009C0FD4
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 009C0080
.text C:\Windows\system32\svchost.exe[1356] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 009C0F68
.text C:\Windows\system32\svchost.exe[1356] msvcrt.dll!_open 77057E48 5 Bytes JMP 00ED0000
.text C:\Windows\system32\svchost.exe[1356] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00ED0058
.text C:\Windows\system32\svchost.exe[1356] msvcrt.dll!system 7708B16F 5 Bytes JMP 00ED0047
.text C:\Windows\system32\svchost.exe[1356] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00ED0FDE
.text C:\Windows\system32\svchost.exe[1356] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00ED0FCD
.text C:\Windows\system32\svchost.exe[1356] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00ED0FEF
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00930000
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 0093001B
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00930F8A
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 0093002C
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00930FE5
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00930047
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00930FCA
.text C:\Windows\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00930FAF
.text C:\Windows\system32\svchost.exe[1356] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00A2000A
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00880FEF
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00880FCD
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00880FDE
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 0087004A
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00870087
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00870076
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00870FB9
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00870039
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00870F46
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00870F6B
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00870F7C
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00870000
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00870ED7
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00870FA8
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00870F8D
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00870FEF
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00870EFC
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00870FCA
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00870065
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00870F35
.text C:\Windows\system32\svchost.exe[1512] msvcrt.dll!_open 77057E48 5 Bytes JMP 008E0FE3
.text C:\Windows\system32\svchost.exe[1512] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 008E0F84
.text C:\Windows\system32\svchost.exe[1512] msvcrt.dll!system 7708B16F 5 Bytes JMP 008E0F95
.text C:\Windows\system32\svchost.exe[1512] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 008E0FC1
.text C:\Windows\system32\svchost.exe[1512] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 008E0FA6
.text C:\Windows\system32\svchost.exe[1512] msvcrt.dll!_wopen 77090570 5 Bytes JMP 008E0FD2
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00860000
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00860FC0
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00860F9B
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00860047
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00860011
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00860058
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00860FDB
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 0086002C
.text C:\Windows\system32\svchost.exe[1512] WS2_32.dll!socket 75E43F00 5 Bytes JMP 00890000
.text C:\Windows\System32\svchost.exe[1632] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 00160000
.text C:\Windows\System32\svchost.exe[1632] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00160022
.text C:\Windows\System32\svchost.exe[1632] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00160011
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 001400C7
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00140111
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 001400F6
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00140FDB
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00140F9E
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00140FC0
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00140098
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00140087
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00140011
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00140F57
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00140047
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00140062
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00140000
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00140F8D
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00140022
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00140F7C
.text C:\Windows\System32\svchost.exe[1632] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00140FAF
.text C:\Windows\System32\svchost.exe[1632] msvcrt.dll!_open 77057E48 5 Bytes JMP 00150000
.text C:\Windows\System32\svchost.exe[1632] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 00150033
.text C:\Windows\System32\svchost.exe[1632] msvcrt.dll!system 7708B16F 5 Bytes JMP 00150022
.text C:\Windows\System32\svchost.exe[1632] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 00150FCD
.text C:\Windows\System32\svchost.exe[1632] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00150FBC
.text C:\Windows\System32\svchost.exe[1632] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00150011
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00110FE5
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 00110036
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00110F9E
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00110FAF
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00110000
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 0011005B
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 1 Byte [E9]
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00110011
.text C:\Windows\System32\svchost.exe[1632] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00110FC0
.text C:\Windows\System32\svchost.exe[1632] WS2_32.dll!socket 75E43F00 5 Bytes JMP 0013000A
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtCreateFile + 6 77484A36 4 Bytes [28, 00, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtCreateFile + B 77484A3B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtMapViewOfSection + 6 77485096 1 Byte [28]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtMapViewOfSection + 6 77485096 4 Bytes [28, 03, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtMapViewOfSection + B 7748509B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenFile + 6 77485146 4 Bytes [68, 00, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenFile + B 7748514B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenProcess + 6 774851F6 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenProcess + B 774851FB 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenProcessToken + 6 77485206 4 Bytes CALL 7648590C C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenProcessToken + B 7748520B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenProcessTokenEx + 6 77485216 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenProcessTokenEx + B 7748521B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenThread + 6 77485276 4 Bytes [68, 01, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenThread + B 7748527B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenThreadToken + 6 77485286 4 Bytes [68, 02, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenThreadToken + B 7748528B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenThreadTokenEx + 6 77485296 4 Bytes CALL 7648599D C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtOpenThreadTokenEx + B 7748529B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtQueryAttributesFile + 6 774853A6 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtQueryAttributesFile + B 774853AB 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtQueryFullAttributesFile + 6 77485456 4 Bytes CALL 76485B5B C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtQueryFullAttributesFile + B 7748545B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtSetInformationFile + 6 77485AA6 4 Bytes [28, 01, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtSetInformationFile + B 77485AAB 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtSetInformationThread + 6 77485B06 4 Bytes [28, 02, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtSetInformationThread + B 77485B0B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtUnmapViewOfSection + 6 77485E26 1 Byte [68]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtUnmapViewOfSection + 6 77485E26 4 Bytes [68, 03, 07, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[1880] ntdll.dll!NtUnmapViewOfSection + B 77485E2B 1 Byte [E2]
.text C:\Windows\system32\svchost.exe[2020] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 001A0000
.text C:\Windows\system32\svchost.exe[2020] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 001A0025
.text C:\Windows\system32\svchost.exe[2020] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 001A0FEF
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 001400A2
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 00140F1E
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 001400B3
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00140FC3
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 00140091
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 0014005B
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 0014004A
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00140039
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00140FD4
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 001400CE
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00140FA8
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00140F97
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00140FEF
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 00140F54
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 0014000A
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 00140F43
.text C:\Windows\system32\svchost.exe[2020] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00140076
.text C:\Windows\system32\svchost.exe[2020] msvcrt.dll!_open 77057E48 5 Bytes JMP 00150FEF
.text C:\Windows\system32\svchost.exe[2020] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 0015003B
.text C:\Windows\system32\svchost.exe[2020] msvcrt.dll!system 7708B16F 5 Bytes JMP 00150FB0
.text C:\Windows\system32\svchost.exe[2020] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 0015000C
.text C:\Windows\system32\svchost.exe[2020] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 00150FC1
.text C:\Windows\system32\svchost.exe[2020] msvcrt.dll!_wopen 77090570 5 Bytes JMP 00150FD2
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 00130000
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 0013004A
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 00130FA8
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 00130FC3
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 00130FE5
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 00130065
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 00130025
.text C:\Windows\system32\svchost.exe[2020] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 00130FD4
.text C:\Windows\system32\svchost.exe[2204] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 0034000A
.text C:\Windows\system32\svchost.exe[2204] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00340FD4
.text C:\Windows\system32\svchost.exe[2204] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00340FE5
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 002E0F43
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 002E00B3
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 002E0F28
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 002E0FCA
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 002E0F54
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 002E0F80
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 002E0062
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 002E0051
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 002E0FE5
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 002E00CE
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 002E0036
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 002E0FA5
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 002E0000
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 002E0087
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 002E001B
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 002E0098
.text C:\Windows\system32\svchost.exe[2204] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 002E0F65
.text C:\Windows\system32\svchost.exe[2204] msvcrt.dll!_open 77057E48 5 Bytes JMP 002F0FEF
.text C:\Windows\system32\svchost.exe[2204] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 002F0042
.text C:\Windows\system32\svchost.exe[2204] msvcrt.dll!system 7708B16F 5 Bytes JMP 002F0027
.text C:\Windows\system32\svchost.exe[2204] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 002F0FC1
.text C:\Windows\system32\svchost.exe[2204] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 002F0016
.text C:\Windows\system32\svchost.exe[2204] msvcrt.dll!_wopen 77090570 5 Bytes JMP 002F0FD2
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 000E0FEF
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 000E0FC3
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 000E0065
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 000E004A
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 000E000A
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 000E0076
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 000E0FD4
.text C:\Windows\system32\svchost.exe[2204] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 000E0025
.text C:\Windows\system32\svchost.exe[2204] WS2_32.dll!socket 75E43F00 5 Bytes JMP 002D0000
.text C:\Windows\Explorer.EXE[3136] ntdll.dll!NtCreateFile 77484A30 5 Bytes JMP 0004000A
.text C:\Windows\Explorer.EXE[3136] ntdll.dll!NtCreateProcess 77484B00 5 Bytes JMP 00040025
.text C:\Windows\Explorer.EXE[3136] ntdll.dll!NtProtectVirtualMemory 77485380 5 Bytes JMP 00040FEF
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!GetStartupInfoA 76021DF0 5 Bytes JMP 000100B0
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreateProcessW 7602202D 5 Bytes JMP 000100F7
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreateProcessA 76022062 5 Bytes JMP 00010F62
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreateNamedPipeW 76051FD6 5 Bytes JMP 00010025
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreatePipe 76054A8B 5 Bytes JMP 0001009F
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!VirtualProtect 760650AB 5 Bytes JMP 00010069
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!LoadLibraryExW 7606B6BF 5 Bytes JMP 00010058
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!LoadLibraryExA 7606BC8B 5 Bytes JMP 00010047
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreateFileW 76070B7D 5 Bytes JMP 00010000
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!GetProcAddress 76071857 5 Bytes JMP 00010112
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!LoadLibraryA 76072884 5 Bytes JMP 00010036
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!LoadLibraryW 760728D2 5 Bytes JMP 00010FA5
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreateFileA 7607291C 5 Bytes JMP 00010FE5
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!GetStartupInfoW 76077CD5 5 Bytes JMP 000100CB
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!CreateNamedPipeA 760AD5BF 5 Bytes JMP 00010FCA
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!WinExec 760AE76D 5 Bytes JMP 000100DC
.text C:\Windows\Explorer.EXE[3136] kernel32.dll!VirtualProtectEx 760AF729 5 Bytes JMP 00010084
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegOpenKeyA 75BDD2ED 5 Bytes JMP 000E0000
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegCreateKeyA 75BDD3C1 5 Bytes JMP 000E0036
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegCreateKeyExA 75BE1B71 5 Bytes JMP 000E0FA5
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegCreateKeyW 75BE1CC0 5 Bytes JMP 000E0047
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegOpenKeyW 75BE3129 5 Bytes JMP 000E0FE5
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegCreateKeyExW 75BEB946 5 Bytes JMP 000E0058
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 1 Byte [E9]
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegOpenKeyExA 75BEBC0D 5 Bytes JMP 000E0011
.text C:\Windows\Explorer.EXE[3136] ADVAPI32.dll!RegOpenKeyExW 75BEBEC4 5 Bytes JMP 000E0FC0
.text C:\Windows\Explorer.EXE[3136] msvcrt.dll!_open 77057E48 5 Bytes JMP 000F0000
.text C:\Windows\Explorer.EXE[3136] msvcrt.dll!_wsystem 7708B04F 5 Bytes JMP 000F0047
.text C:\Windows\Explorer.EXE[3136] msvcrt.dll!system 7708B16F 5 Bytes JMP 000F0FC6
.text C:\Windows\Explorer.EXE[3136] msvcrt.dll!_creat 7708ED29 5 Bytes JMP 000F0FD7
.text C:\Windows\Explorer.EXE[3136] msvcrt.dll!_wcreat 7709038E 5 Bytes JMP 000F002C
.text C:\Windows\Explorer.EXE[3136] msvcrt.dll!_wopen 77090570 5 Bytes JMP 000F0011
.text C:\Windows\Explorer.EXE[3136] WININET.dll!InternetOpenA 75977DE4 5 Bytes JMP 00610FEF
.text C:\Windows\Explorer.EXE[3136] WININET.dll!InternetOpenW 75979D60 5 Bytes JMP 00610000
.text C:\Windows\Explorer.EXE[3136] WININET.dll!InternetOpenUrlA 7597DBD8 5 Bytes JMP 0061001B
.text C:\Windows\Explorer.EXE[3136] WININET.dll!InternetOpenUrlW 759CDD6C 5 Bytes JMP 00610FCA
.text C:\Windows\Explorer.EXE[3136] WS2_32.dll!socket 75E43F00 5 Bytes JMP 03DD0000
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtCreateFile + 6 77484A36 4 Bytes [28, 00, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtCreateFile + B 77484A3B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtMapViewOfSection + 6 77485096 1 Byte [28]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtMapViewOfSection + 6 77485096 4 Bytes [28, 03, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtMapViewOfSection + B 7748509B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenFile + 6 77485146 4 Bytes [68, 00, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenFile + B 7748514B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenProcess + 6 774851F6 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenProcess + B 774851FB 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenProcessToken + 6 77485206 4 Bytes CALL 7648690C C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenProcessToken + B 7748520B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenProcessTokenEx + 6 77485216 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenProcessTokenEx + B 7748521B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenThread + 6 77485276 4 Bytes [68, 01, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenThread + B 7748527B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenThreadToken + 6 77485286 4 Bytes [68, 02, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenThreadToken + B 7748528B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenThreadTokenEx + 6 77485296 4 Bytes CALL 7648699D C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtOpenThreadTokenEx + B 7748529B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtQueryAttributesFile + 6 774853A6 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtQueryAttributesFile + B 774853AB 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtQueryFullAttributesFile + 6 77485456 4 Bytes CALL 76486B5B C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtQueryFullAttributesFile + B 7748545B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtSetInformationFile + 6 77485AA6 4 Bytes [28, 01, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtSetInformationFile + B 77485AAB 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtSetInformationThread + 6 77485B06 4 Bytes [28, 02, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtSetInformationThread + B 77485B0B 1 Byte [E2]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtUnmapViewOfSection + 6 77485E26 1 Byte [68]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtUnmapViewOfSection + 6 77485E26 4 Bytes [68, 03, 17, 00]
.text C:\Users\Kim\AppData\Local\Google\Chrome\Application\chrome.exe[4080] ntdll.dll!NtUnmapViewOfSection + B 77485E2B 1 Byte [E2]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000051 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- EOF - GMER 1.0.15 ----