Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with XP Recovery & Google keeps redirecting


  • This topic is locked This topic is locked
3 replies to this topic

#1 Michael W St. John

Michael W St. John

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:11 AM

Posted 20 May 2011 - 03:04 PM

Received pop up message in typical Rogue Virus fashion. Disabled my task manager and hid user files. Restarted in 'Safe Mode with Networking' and attempted to run TDSSKiller as instructed in article: http://www.bleepingcomputer.com/virus-removal/remove-windows-xp-recovery . TDSSKiller did not detect any root kits. When attempting to get Malwarebytes from Google, all links continue to redirect to fake antivirus/spam websites. Obviously there is a root kit running that cannot be detected. Any help would be much appreciated!

This is the DDS log:

.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by Administrator at 12:52:45 on 2011-05-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2479 [GMT -5:00]
.
AV: Symantec Endpoint Protection *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\MSSQL7\binn\sqlservr.exe
C:\MSSQL7\Binn\sqlservr.dll
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\WINDOWS\system32\SearchIndexer.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Vital\POS2000\BIN\vAppCon.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
mDefault_Page_URL = hxxp://atm.mdrt.org
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [OdTray.exe] "c:\program files\juniper networks\odyssey access client\OdTray.exe"
mRun: [<NO NAME>]
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Client Access Service] "c:\program files\ibm\client access\cwbsvstr.exe"
mRun: [Client Access Help Update] "c:\program files\ibm\client access\cwbinhlp.exe"
mRun: [Client Access Check Version] "c:\program files\ibm\client access\cwbckver.exe" LOGIN
mRun: [Client Access Express Welcome] "c:\program files\ibm\client access\cwbwlwiz.exe"
mRun: [Client Access PC5250 Sound] "c:\program files\ibm\client access\emulator\pcssnd.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [AppCon] "c:\program files\vital\pos2000\bin\vAppCon.exe"
mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mPolicies-system: MaxGPOScriptWait = 30 (0x1e)
mPolicies-system: DisableTaskMgr = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222295136570
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://juniper.net/dana-cached/setup/JuniperSetupSP1.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Notify: igfxcui - igfxdev.dll
Notify: OdysseyClient - odyEvent.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nlemsql;NLEMSQL;c:\windows\system32\drivers\nlemsql.sys [2008-10-24 70224]
R0 odFips;odFips;c:\windows\system32\drivers\odFIPS.sys [2008-4-30 254208]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-7-26 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-7-26 108392]
R2 JuniperAccessService;Juniper Unified Network Service;c:\program files\common files\juniper networks\juns\dsAccessService.exe [2007-12-20 83320]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2008-9-19 2514944]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-5-11 105592]
R3 jnprna;Juniper Network Agent Miniport;c:\windows\system32\drivers\jnprna.sys [2007-10-4 390528]
R3 JnprVaMgr;Juniper Networks Virtual Adapter Manager Service;c:\windows\system32\drivers\jnprvamgr.sys [2007-10-4 29312]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110519.033\NAVENG.SYS [2011-5-20 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110519.033\NAVEX15.SYS [2011-5-20 1542392]
S2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2008-7-26 2240944]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-7-26 23888]
S3 EacService;Juniper TNC Endpoint Assessment;c:\program files\common files\juniper networks\tnc client\jTnccService.exe [2008-4-30 116008]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
.
=============== Created Last 30 ================
.
2011-05-20 16:01:54 -------- d-----w- c:\windows\pss
2011-05-20 15:56:36 88752 ----a-w- c:\windows\system32\drivers\klmdb.sys
2011-05-20 15:56:19 -------- d-----w- C:\TDSSKiller_Quarantine
2011-05-20 15:39:54 -------- d-----w- c:\documents and settings\administrator\application data\alot
2011-05-20 15:32:57 344576 ----a-w- c:\documents and settings\all users\application data\18210596.exe
2011-05-20 15:23:29 422400 ----a-w- c:\documents and settings\all users\application data\MEXFxpGUVShIHWB.exe
.
==================== Find3M ====================
.
2011-04-13 17:57:21 167936 ----a-w- c:\windows\system32\drivers\WpsHelper.sys
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ------w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3160815AS rev.4.CCC -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-16
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xBA18E8B0]<<
_asm { PUSH ECX; MOV EAX, [ESP+0x8]; PUSH EBX; PUSH EBP; PUSH ESI; PUSH EDI; CMP EAX, [0xba194904]; JNZ 0x22; MOV EBX, [ESP+0x1c]; CALL 0xfffffffffffffcc0; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A445AB8]
3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x8A3FCF08]
\Driver\Disk[0x8A3AA7E8] -> IRP_MJ_CREATE -> 0xBA18E8B0
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
.
============= FINISH: 12:53:43.99 ===============


GMER REPORT

GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-20 15:02:47
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-16 ST3160815AS rev.4.CCC
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kfpiqkob.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwAllocateVirtualMemory [0xB92EB1C0]
SSDT 8A4DFEA0 ZwConnectPort
SSDT SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation) ZwCreateThread [0xB9D8B7E0]
SSDT SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation) ZwMapViewOfSection [0xB9D8B210]
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB92EB2F0]
SSDT SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation) ZwQueryDefaultLocale [0xB9D8B830]
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwWriteVirtualMemory [0xB92EB420]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeReleaseInStackQueuedSpinLockFromDpcLevel + B5D 80541665 5 Bytes JMP B9D8CC30 SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation)
.text ndiswan.sys B93F0000 57 Bytes [FE, 66, 2B, CA, 0F, B7, C0, ...]
.text ndiswan.sys B93F003A 14 Bytes [89, 40, 04, 89, 00, 8D, 86, ...] {MOV [EAX+0x4], EAX; MOV [EAX], EAX; LEA EAX, [ESI+0xb8]; MOV [EAX+0x4], EAX}
.text ndiswan.sys B93F0049 203 Bytes [00, 8D, 86, A8, 00, 00, 00, ...]
.text ndiswan.sys B93F0115 214 Bytes JMP B93EF8FD \SystemRoot\system32\DRIVERS\ndiswan.sys (MS PPP Framing Driver (Strong Encryption)/Microsoft Corporation)
.text ndiswan.sys B93F01EC 51 Bytes [F6, 43, 0C, 01, 0F, 84, DF, ...]
.text ...
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xA904CA00]
? C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
.text ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes [E9, 38, D2, E5, E4] {JMP 0xffffffffe4e5d23d}
.text ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes [E9, 32, D2, E5, E4] {JMP 0xffffffffe4e5d237}
.text ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes [E9, AC, D1, E5, E4] {JMP 0xffffffffe4e5d1b1}
.text ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes [E9, 56, D1, E5, E4] {JMP 0xffffffffe4e5d15b}
.text ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes [E9, 60, D1, E5, E4] {JMP 0xffffffffe4e5d165}
.text ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes [E9, EA, CE, E5, E4] {JMP 0xffffffffe4e5ceef}
.text ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes [E9, A4, CE, E5, E4] {JMP 0xffffffffe4e5cea9}
.text ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes [E9, AE, CE, E5, E4] {JMP 0xffffffffe4e5ceb3}
.text ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes [E9, 58, CA, E5, E4] {JMP 0xffffffffe4e5ca5d}
.text ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes [E9, 92, C8, E5, E4] {JMP 0xffffffffe4e5c897}
.text ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes [E9, 5C, C7, E5, E4] {JMP 0xffffffffe4e5c761}
.text ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes [E9, F6, C6, E5, E4] {JMP 0xffffffffe4e5c6fb}

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[296] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe[308] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[388] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[552] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[596] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\binn\sqlservr.exe[828] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\MSSQL7\Binn\sqlservr.dll[836] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\atchksrv.exe[848] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\IoctlSvc.exe[972] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe[1088] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\UNS.exe[1100] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1140] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre6\bin\jqs.exe[1224] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1248] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1260] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe[1400] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Intel\AMT\LMS.exe[1444] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1476] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1604] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxtray.exe[1640] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\hkcmd.exe[1660] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxpers.exe[1716] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1752] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1800] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1884] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1896] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1924] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1964] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe[2040] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[2064] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2104] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[2208] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Vital\POS2000\BIN\vAppCon.exe[2500] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text c:\program files\lenovo\system update\suservice.exe[2584] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\igfxsrvc.exe[2612] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[2644] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2724] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[2828] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2864] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2976] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3288] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[3420] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtCreateFile + 5 7C90D0B3 5 Bytes JMP 6176A2F0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtCreateKey + 5 7C90D0F3 5 Bytes JMP 6176A32A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtCreateThread + 5 7C90D1B3 5 Bytes JMP 6176A364 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtDeleteFile + 5 7C90D243 5 Bytes JMP 6176A39E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtDeleteValueKey + 5 7C90D273 5 Bytes JMP 6176A3D8 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtMapViewOfSection + 5 7C90D523 5 Bytes JMP 6176A412 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtOpenFile + 5 7C90D5A3 5 Bytes JMP 6176A44C C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtOpenKey + 5 7C90D5D3 5 Bytes JMP 6176A486 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtRenameKey + 5 7C90DA63 5 Bytes JMP 6176A4C0 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtSetInformationFile + 5 7C90DC63 5 Bytes JMP 6176A4FA C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtSetValueKey + 5 7C90DDD3 5 Bytes JMP 6176A534 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3856] ntdll.dll!NtTerminateProcess + 5 7C90DE73 5 Bytes JMP 6176A56E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs nlemsql.sys
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \Driver\Disk \GLOBAL??\ACPI#PNP0303#2&da1a3ff&0 BA18E8B0

---- Modules - GMER 1.0.15 ----

Module (noname) (*** hidden *** ) BA198000-BA1A2000 (40960 bytes)

---- Threads - GMER 1.0.15 ----

Thread System [4:128] BA19D440
Thread System [4:132] BA19D440
Thread System [4:136] BA19D440
Thread System [4:140] BA19D440
Thread System [4:148] BA18F710
Thread System [4:152] BA18F710
Thread System [4:156] BA18F710
Thread System [4:160] BA18F710

---- EOF - GMER 1.0.15 ----

BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:11 AM

Posted 26 May 2011 - 05:20 AM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • Please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.


We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.


In order for me to see the status of the infection I will need a new set of logs to start with.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

DeFogger:

  • Please download DeFogger to your desktop.

    Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger may ask you to reboot the machine, if it does - click OK
Do not re-enable these drivers until otherwise instructed.

Download DDS:

  • Please download DDS by sUBs from one of the links below and save it to your desktop:

    Posted Image
    Download DDS and save it to your desktop

    Link1
    Link2
    Link3

    Please disable any anti-malware program that will block scripts from running before running DDS.

    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply





Scan With RKUnHooker

  • Please Download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth,. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.
Copy the entire contents of the report and paste it in a reply here.

Note** you may get this warning it is ok, just ignore

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


"just click on Cancel, then Accept".


information and logs:

  • In your next post I need the following

  • .logs from DDS
  • log from RKUnHooker
  • let me know of any problems you may have had

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:11 AM

Posted 29 May 2011 - 03:45 AM

Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:11 AM

Posted 31 May 2011 - 11:34 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users