Thanks a lot. I have taken the right precautions and now never have more than one PC at a time attached to the LAN. The first infected one is only connected to the internet for brief periods.
I have had to separate the GMER log into several replies, followed by the Hijackthis log.
GMER 1.0.12.12244 -
http://www.gmer.net
Rootkit scan 2007-05-31 15:59:02
Windows 5.1.2600 Service Pack 1
—- System - GMER 1.0.12 —-
SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwCreateKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwDeleteValueKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwEnumerateKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwEnumerateValueKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwOpenKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys ZwTerminateThread
SSDT \??\C:\WINDOWS\System32\PavSRK.sys ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.12 —-
? C:\WINDOWS\system32\xpdx.sys The system cannot find the file specified.
? C:\WINDOWS\System32\PavTPK.sys The system cannot find the file specified.
? C:\WINDOWS\System32\PavSRK.sys The system cannot find the file specified.
? system32\drivers\av5flt.sys The system cannot find the file specified.
? C:\WINDOWS\System32\DRIVERS\COMFiltr.sys The system cannot find the file specified.
.text ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
—- User code sections - GMER 1.0.12 —-
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4B, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4E, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6F, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 51, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 72, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 54, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 57, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 5A, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5D, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 60, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 75, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 63, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 66, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 78, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7B, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 69, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6C, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7E, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F380F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3B0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 45, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3E0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F350F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 42, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 48, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FAA0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F950F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F920F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA10F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8F0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A5, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F980F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8C0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA70F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9C, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9F, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F890F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F860F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F830F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F800F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\Program Files\Panda Software\Panda Internet Security 2007\SrvLoad.exe[1316] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717