I am having some trouble posting the Gmer log. It says you must enter a post. I will try posting just half the log here:
GMER 1.0.15.15570 -
http://www.gmer.net
Rootkit scan 2011-03-24 22:16:32
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000054 ST325031 rev.3.AH
Running: gmer.exe; Driver: C:\Users\Ream\AppData\Local\Temp\kwldrpoc.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x87463CDC]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x87463ECE]
SSDT \SystemRoot\system32\drivers\TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwTerminateProcess [0x87498BD6]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x874640D6]
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 209 868ED98C 8 Bytes [DC, 3C, 46, 87, CE, 3E, 46, …]
.text ntkrnlpa.exe!KeSetEvent + 621 868EDDA4 4 Bytes [D6, 8B, 49, 87] {SALC ; MOV ECX, [ECX-0x79]}
.text ntkrnlpa.exe!KeSetEvent + 6E5 868EDE68 4 Bytes [D6, 40, 46, 87]
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x90C02340, 0x3DA3F7, 0xE8000020]
? \ArcName\multi(0)disk(0)rdisk(0)partition(1)\Windows\system32\drivers\PctWfpFilter.sys The system cannot find the path specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[540] KERNEL32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\wininit.exe[592] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[604] KERNEL32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\services.exe[640] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[640] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\services.exe[640] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\services.exe[640] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\services.exe[640] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\services.exe[640] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\services.exe[640] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\services.exe[640] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\services.exe[640] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\services.exe[640] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\services.exe[640] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\services.exe[640] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\services.exe[640] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\services.exe[640] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 7120000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 70A2000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7103000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 70B8000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 70BB000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 709C000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 70D0000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 70D6000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7163000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7099000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 716E000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 70CD000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 7123000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 7130000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 7126000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 70A8000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 70CA000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 712D000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 70EC000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 70D3000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 709F000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 7106000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 70EF000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 70A5000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7100000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 70E5000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 70B5000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7160000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 715A000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 7154000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 70D9000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 70DC000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 7157000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 70DF000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 715D000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 714E000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 7151000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 714B000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 70E2000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [0C, 71] {OR AL, 0x71}
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 70C1000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 70BE000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 70C4000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 70AB000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 70C7000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 70AE000A
.text C:\Windows\system32\winlogon.exe[664] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 70F6000A
.text C:\Windows\system32\winlogon.exe[664] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 70F9000A
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\lsass.exe[684] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\lsm.exe[700] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Program Files\Spyware Doctor\TFEngine\TFService.exe[748] kernel32.dll!CreateRemoteThread + 175 770BCAAA 4 Bytes [00, 00, 6F, 71]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\svchost.exe[840] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1F, 71]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7162000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714D000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 715F000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C5000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7047000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A8000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705D000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7060000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7041000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7075000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7159000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707B000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715C000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7108000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7123000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703E000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710F000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7072000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C8000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D5000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CB000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704D000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706F000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D2000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7091000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7078000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7044000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AB000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7094000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704A000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A5000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708A000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705A000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7105000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FF000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F9000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707E000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7081000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FC000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7084000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7102000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F3000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F6000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F0000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7087000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [11, 71]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7156000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7115000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B1, 70] {MOV CL, 0x70}
.text C:\Windows\system32\svchost.exe[916] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7066000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7063000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7069000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7050000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706C000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7053000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709B000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] wininet.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] wininet.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [07, 71]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [33, 71]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70AD000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7029000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7090000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 703F000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7042000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7023000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7057000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 705D000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 70F0000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 710B000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7131000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7020000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 70F7000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7054000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70B0000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70BD000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70B3000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 702F000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7051000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70BA000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7073000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 705A000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7026000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 7093000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7076000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 712E000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 702C000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 708D000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 706C000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 703C000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyExA 76C439AB 4 Bytes [FF, 25, 1E, 00]
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyExA + 5 76C439B0 1 Byte [70]
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70E7000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70E1000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7060000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7063000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70E4000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7066000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70EA000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70DB000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70DE000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70D8000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7069000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [F9, 70]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7128000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 70FD000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [10, 71]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [99, 70]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7048000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7045000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712B000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 704B000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7032000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 704E000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7035000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 710E000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7083000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7086000A
.text C:\Windows\system32\taskeng.exe[1048] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 707C000A
.text C:\Windows\system32\taskeng.exe[1048] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7079000A
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1E, 71]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714D000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70BB000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 703D000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 709E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7053000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7056000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7037000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706B000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7071000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7107000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7122000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7034000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7068000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70BE000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70CB000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C1000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7043000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7065000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70C8000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7087000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 706E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703A000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A1000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708A000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7040000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 709B000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7080000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7050000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7104000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F5000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70EF000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7074000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7077000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F2000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707A000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7101000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70E9000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70EC000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E6000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 707D000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [10, 71]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7114000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A7, 70]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705C000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7059000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 705F000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7046000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7062000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7049000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7091000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7094000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegCreateKeyA