This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Seriously Compromised

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC has been invaded by something just this morning. I am sure it was an email (sbject "Woody Allen committed suicide this morning") with a single attachment Full_video.zip. I opened the attachment (yes I know!!) and it appeared to contain an AVI file.

Since then various parts of my setup have stopped working (at least Windows Media Player, add/remove programs, IIS manager). Every few minutes I get a popup message saying Windows has detected spyware infection and inviting me to download an update which I am ignoring. I installed Norton AV and did a scan which claimed to have detected and removed dialer.dialerplatform but it made no difference so I unintsalled NAV. I subsequently installed Stopzilla and it seems to be running (there is an icon in the system tray) but I cannot start it up.

Here is my hijackthis log. I would appreciate any help you can offer.

Logfile of HijackThis v1.99.1
Scan saved at 11:38:32, on 29/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\WinPortrait\wpctrl.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ipmon.exe
C:\WINDOWS\system32\ipmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\WinPortrait\floater.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\windows\system32\spoolvq3.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ipmon] ipmon.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [SvcManager] spoolvq3.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4A026B12-94F3-4D2F-A468-96AA55DE20A5} (NetCamPlayerWeb11g Control) - http://192.168.0.5/img/NetCamPlayerWeb11g.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173021502021
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cepstral License Server - Cepstral, LLC - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
Hi spierian,

You should know that your computer has been infected by multiple backdoor trojans. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning. In this case the warning about passwords is only likely to apply from the time of infection, but I can't be sure how long the machine has been infected so please take whatever precautions are necessary.

Next, it is vital that you have an antivirus product running at all times. I can see Panda and a Symantec (Norton) product installed, but I'm not sure either is running. If you have more than one product installed, please choose one to use and uninstall the others, multiple antivirus programs can conflict and cause system problems without increasing your security. If you do not have an antivirus program installed, either install one of your choice or download and install one of these free packages:
AVG Antivirus: http://free.grisoft.com/doc/1
Antivir: http://www.free-av.com/

Then update the definitions, run a full system scan and allow it to quarantine/delete anything it finds. Also, take a note of where the log file is stored and post a copy in your next response.

Please do not proceed with the instructions until you have (only) one antivirus program installed and providing real-time protection. If you have problems the stop and let me know.

Please print/save a copy of these instructions because we will be using Safe Mode, during which time you won't have access to the internet.

Next, download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Download Deckard's System Scanner (DSS) to your Desktop.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply
Once complete, please post the antivirus scan log, the SDFix log and the Deckard's System Scanner reports - I won't need a new HijackThis log this time as the DSS report includes one.
Many tahnks for your instructions.

I have followed the recovery instructions as far as possible. I ran Panda (no other AV software is running) then did the subsequent steps. The final stage (running dss.exe) failed with a "dss.exe has encountered an error and has to close". However I have attached below the reports from Panda and sdfix

1. I cannot get rid of Stopzilla which I installed and ran yesterday. It does not appear in the Add/Remove Programs list nor in the list from "My Unistaller" (by URSoft). I think there has been some corruption of Windows.

2. I had decided to clean this PC completely and in preparation I copied a load of recent files including my outlook.pst to another pc on my wireless LAN. I started this second PC (after the copy) and installed the driver for my Samsung monitor. Thereafter that second PC refuses to boot fully! In normal or safe mode it gets the Windows welcome tune and then the desktop remains blank with no icons. I can do ctrl-alt-del and restart that way. I suspect I have somehow infected that PC from the first - is that possible? Any idea how to recover? Anyway, after that debacle, I decided to try and recover the orginal PC.

3. After the cleansing steps (except DSS.exe of course) I am still getting "Messanger Service" notification boxes every few minutes saying I should download Registry Update from www.registryalert.net (sometimes the url is different) so something wrong is still going on.


PANDA REPORT
=============
Panda Internet Security 2007 incident report
Filter selected:Virus detected, Suspicious file, Dangerous file, Script execution, Phone connection, Connection attempt, Port scan attack, Denial of service attack, Spoofing, Attacking IP address blocked, Enabled, Disabled, Update, Scan started, Scan complete, Date: All
INCIDENT NOTIFIED BY DATE-TIME RESULT ADDITIONAL INFORMATION
————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Hacking tool detected: Rootkit/NTRoo… Antivirus protection 30/05/07 12:48:00 Disinfected Path: c:\windows\system32\ksys.sys
Hacking tool detected: Rootkit/Goldun.AG Antivirus protection 30/05/07 12:48:58 Disinfected Path: c:\windows\system32\ntio256.sys
Potentially unwanted program detecte… Antivirus protection 30/05/07 12:49:16 Disinfected Path: c:\windows\system32\ipmon.exe
Adware detected: Adware/SpySheriff Antivirus protection 30/05/07 12:53:23 Disinfected Path: c:\documents and settings\administrator\local settings\temporary internet files\content.ie5bo3uxmz\mjaibj[1].htm
Virus detected: Trj/Downloader.NUS Antivirus protection 30/05/07 12:53:23 Disinfected Path: c:\documents and settings\administrator\local settings\temporary internet files\content.ie5\jnz0w8zl\odnkhwgtd[1].htm
Suspicious program detected Protection against unknown… 30/05/07 12:53:29 Blocked File: C:\WINDOWS\SYSTEM32\SPOOLVQ3.EXE
Suspicious program detected Protection against unknown… 30/05/07 12:58:40 Blocked File: C:\WINDOWS\SYSTEM32\SPOOLVQ3.EXE
Hacking tool detected: Rootkit/NTRoo… Antivirus protection 30/05/07 12:59:13 Disinfected Path: c:\windows\system32\ksys.sys
Virus detected: Trj/Downloader.NUS Antivirus protection 30/05/07 12:59:20 Disinfected Path: c:\documents and settings\administrator\local settings\temporary internet files\content.ie5\jnz0w8zl\odnkhwgtd[1].htm
Adware detected: Adware/SpySheriff Antivirus protection 30/05/07 12:59:20 Disinfected Path: c:\documents and settings\administrator\local settings\temporary internet files\content.ie5\hjsihw1k\mjaibj[1].htm
Scan started On-demand antivirus scan 30/05/07 13:01:34 Scan: Scanning the whole syste
Virus detected: trj/winopts.a On-demand antivirus scan 30/05/07 13:01:40 Disinfected Path: c:\windows\system32\rpcc.exe
Potentially unwanted program detecte… On-demand antivirus scan 30/05/07 13:01:56 Deleted Path: c:\windows\downloaded program files\udc6_0001_d19m1908netinstaller.exe
Dialer detected: dialer.su On-demand antivirus scan 30/05/07 13:02:01 Disinfected Path: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\switch
Adware detected: Adware/SpySheriff On-demand antivirus scan 30/05/07 13:02:10 Disinfected Path: C:\uxmwyj.exe
Virus detected: Trj/Downloader.NUS On-demand antivirus scan 30/05/07 13:02:33 Disinfected Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5BO3UXMZ\odnkhwgtd[1].htm
Adware detected: Adware/SpySheriff On-demand antivirus scan 30/05/07 13:02:33 Disinfected Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\T0GQFPW3\mjaibj[1].htm
Scan started On-demand antivirus scan 30/05/07 13:04:47 Scan:
Virus detected: trj/winopts.a On-demand antivirus scan 30/05/07 13:05:09 Disinfected Path: c:\windows\system32\rpcc.exe
Scan complete On-demand antivirus scan 30/05/07 13:05:43 Scan:
Update Update system 30/05/07 13:04:44 Correct Total threat signatures: 504084
Update Update system 30/05/07 13:04:50 Correct New version:
Hacking tool detected: Rootkit/NTRoo… On-demand antivirus scan 30/05/07 13:18:58 Deleted Path: C:\WINDOWS\system32\ksys.sys
Hacking tool detected: Rootkit/Goldun.AG On-demand antivirus scan 30/05/07 13:19:12 Deleted Path: C:\WINDOWS\system32\ntio256.sys
Virus detected: Trj/Seet.A On-demand antivirus scan 30/05/07 13:19:17 Disinfected Path: C:\WINDOWS\system32\protector.exe
Scan complete On-demand antivirus scan 30/05/07 13:25:31 Scan: Scanning the whole syste
=============================================================================





SDFIX REPORT.TXT
=================

SDFix: Version 1.85

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
NDnet1
ntio256
Runtime

ImagePath:
\??\C:\WINDOWS\System32\ksys.sys
\??\C:\WINDOWS\system32\ntio256.sys
\??\C:\WINDOWS\System32\drivers\runtime.sys

NDnet1 - Deleted
ntio256 - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\-16102~1 - Deleted
C:\WINDOWS\system32\7_exception.nls - Deleted
C:\WINDOWS\system32\ksys.sys - Deleted
C:\WINDOWS\system32\max1d1641.exe - Deleted
C:\WINDOWS\Temp\startdrv.exe - Deleted



Removing Temp Files…

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
——————


Rootkit runtime2 Found, Use a Rootkit scanner !

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\FlashFXP\\flashfxp.exe"="C:\\Program Files\\FlashFXP\\flashfxp.exe:*:Enabled:FlashFXP v3"
"C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
"c:\\windows\\system32\\spoolvq3.exe"="c:\\windows\\system32\\spoolvq3.exe:*:Enabled:spoolvq3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\FlashFXP\\flashfxp.exe"="C:\\Program Files\\FlashFXP\\flashfxp.exe:*:Enabled:FlashFXP v3"
"C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"

Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes:

C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Off8E.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Off8Eh.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Off8Es.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Pro91.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Pro91h.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Pro91s.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Qui8Fh.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Qui8Fs.tmp
C:\Documents and Settings\Administrator\Application Data\Roxio\Dragon\DiscInfoCache\SONY_____DVD_RW_AW-G170A__1.71_300_DICV018_DRGV2050108.TMP
C:\keys\WORK\COI\2006 Onevoice\SIO awayday\~WRL3956.tmp
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG

Finished
Just tried dss.exe again and it worked this time. Here are the reports.





MAIN.TXT
=====================

Deckard's System Scanner v20070426.43
Run by [removed] on 2007-05-30 at 14:32:54
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
6: 2007-05-30 13:32:56 UTC - RP6 - Deckard's System Scanner Restore Point
5: 2007-05-30 13:02:35 UTC - RP5 - Deckard's System Scanner Restore Point
4: 2007-05-30 11:45:11 UTC - RP4 - Installed Panda Internet Security 2007
3: 2007-05-30 11:39:03 UTC - RP3 - Installed AVG 7.5
2: 2007-05-29 16:28:12 UTC - RP2 - Installed Windows Installer KB893803v2.


– First Restore Point –
1: 2007-05-29 16:27:55 UTC - RP1 - Software Distribution Service 2.0


Performed disk cleanup.


– HijackThis Clone ————————————————————

Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-05-30 14:33:15
Platform: Windows XP Service Pack 1 (5.01.2600)
MSIE: Internet Explorer (6.0.2800.1106)

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PAVSRV51.EXE
C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrlS.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PAVFNSVR.EXE
C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\apvxdwin.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\SrvLoad.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe
C:\Program Files\WinPortrait\floater.exe
C:\WINDOWS\system32\LVComS.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar2.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O3 - Toolbar: (no name) - SITEguard - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ipmon] ipmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\pnrpnsp.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\pnrpnsp.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4A026B12-94F3-4D2F-A468-96AA55DE20A5} (NetCamPlayerWeb11g Control) - http://192.168.0.5/img/NetCamPlayerWeb11g.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173021502021
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180455924609
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O20 - Winlogon Notify: avldr - C:\WINDOWS\System32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\System32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
O23 - Service: Cepstral License Server - Cepstral, LLC - "C:\Program Files\Cepstral\bin\CepstralLicSrv.exe"
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Microsoft Corp., Veritas Software - C:\WINDOWS\System32\dmadmin.exe /com
O23 - Service: Google Updater Service (gusvc) - Google - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
O23 - Service: iPod Service - Unknown owner - "C:\Program Files\iPod\bin\iPodService.exe"
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - "C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrls.exe"
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - "C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe"
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - "C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe"
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - "C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe"
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - "c:\program files\panda software\panda internet security 2007\firewall\PSHOST.EXE"
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - "C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe"
O23 - Service: Symantec Core LC - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - "C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe"
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - "C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe"


– File Associations ———————————————————–

.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser %1,%*
.js - JSFile - shell\open\command - C:\PROGRA~1\PANDAS~1\PANDAI~1\PavScrip.exe "%1" %*
.vbs - VBSFile - shell\open\command - C:\PROGRA~1\PANDAS~1\PANDAI~1\PavScrip.exe "%1" %*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 szkg - c:\windows\system32\drivers\szkg.sys
Hi spierian,

Those logs show your machine as severely infected, I should tell you that it could take a while to clean this machine, and I hope you took notice of the warning I gave above, if it applies to you the risk is real and the sooner you take precautions the less likely you are to have a problem.

I can help with removing Stopzilla but not until we've cleaned the malware.

With regard to the other computers on your LAN, it's very possible that they are also infected, and there is a risk that the one we are cleaning will be reinfected by the other machine while we are working so it's best to not have them connected to the LAN at the same time. In any case, I strongly recommend you disconnect this machine from the network and the internet when we aren't working on it for now.

If you would like help with another machine then you should post a log with a description of symptoms, probably best done when we are finished with this one.

If you wish to transfer files from this machine to another, you should be able to do so but you must scan everything before it is accessed in any way on the new system. I recommend you use Kaspersky Online Scanner for this job.

Download Gmer to your Desktop from here:
http://www.gmer.net/gmer.zip
  • Unzip the program onto your Desktop
  • Disconnect from internet and close all running programs
  • Double click gmer.exe, let the gmer.sys driver load if asked
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say OK
  • If no warning….Check that the Rootkit tab is selected and click the Scan button - don't change any settings before you do so
  • Once the scan is complete, click the Copy button
  • Open Notepad and hit Ctrl+V to paste the log and then save the log to your desktop
Once complete, please post the GMER log and a new HijackThis log.
Thanks a lot. I have taken the right precautions and now never have more than one PC at a time attached to the LAN. The first infected one is only connected to the internet for brief periods.

I have had to separate the GMER log into several replies, followed by the Hijackthis log.


GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-31 15:59:02
Windows 5.1.2600 Service Pack 1


—- System - GMER 1.0.12 —-

SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwCreateKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwDeleteValueKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwEnumerateKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwEnumerateValueKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwOpenKey
SSDT \SystemRoot\system32\drivers\runtime2.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys ZwTerminateThread
SSDT \??\C:\WINDOWS\System32\PavSRK.sys ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.12 —-

? C:\WINDOWS\system32\xpdx.sys The system cannot find the file specified.
? C:\WINDOWS\System32\PavTPK.sys The system cannot find the file specified.
? C:\WINDOWS\System32\PavSRK.sys The system cannot find the file specified.
? system32\drivers\av5flt.sys The system cannot find the file specified.
? C:\WINDOWS\System32\DRIVERS\COMFiltr.sys The system cannot find the file specified.
.text ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]

—- User code sections - GMER 1.0.12 —-

.text C:\WINDOWS\explorer.exe[192] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\explorer.exe[192] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\explorer.exe[192] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[192] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\explorer.exe[192] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\alg.exe[272] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\alg.exe[272] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\alg.exe[272] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\nvsvc32.exe[308] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\Program Files\Panda Software\Panda Internet Security 2007\FIREWALL\PSHost.exe[328] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[512] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\spoolsv.exe[512] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\svchost.exe[548] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\svchost.exe[548] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[548] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe[560] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4B, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4E, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6F, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 51, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 72, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 54, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 57, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 5A, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5D, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 60, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 75, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 63, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 66, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 78, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7B, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 69, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6C, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7E, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F380F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3B0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 45, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3E0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F350F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 42, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 48, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FAA0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F950F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F920F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA10F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8F0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A5, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F980F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8C0F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA70F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9C, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9F, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F890F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F860F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F830F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[828] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F800F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\msdtc.exe[1068] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\msdtc.exe[1068] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\winlogon.exe[1184] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\services.exe[1228] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\lsass.exe[1240] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764
.text C:\Program Files\Panda Software\Panda Internet Security 2007\SrvLoad.exe[1316] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717
GMER LOG PART 2 .text C:\Program Files\Panda Software\Panda Internet Security 2007\SrvLoad.exe[1316] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\SrvLoad.exe[1316] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\SrvLoad.exe[1316] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrlS.exe[1324] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrlS.exe[1324] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrlS.exe[1324] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrlS.exe[1324] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe[1376] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe[1376] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe[1376] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe[1376] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\svchost.exe[1432] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\svchost.exe[1432] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\svchost.exe[1432] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\svchost.exe[1432] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe[1496] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe[1496] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe[1496] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe[1496] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\svchost.exe[1536] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1536] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1536] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\svchost.exe[1536] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\svchost.exe[1536] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\svchost.exe[1536] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVFNSVR.EXE[1588] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVFNSVR.EXE[1588] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVFNSVR.EXE[1588] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVFNSVR.EXE[1588] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVSRV51.EXE[1660] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVSRV51.EXE[1660] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVSRV51.EXE[1660] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PAVSRV51.EXE[1660] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE[1672] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE[1672] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE[1672] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE[1672] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 76, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 80, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\svchost.exe[1808] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\svchost.exe[1808] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\svchost.exe[1808] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\svchost.exe[1808] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FAC0F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA30F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A7, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F9A0F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1808] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ A1, 5F ] .text C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe[1864] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe[1864] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe[1864] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe[1864] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe[1980] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\svchost.exe[1988] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[1988] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\svchost.exe[1988] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\svchost.exe[1988] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\svchost.exe[1988] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\svchost.exe[1988] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe[2224] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe[2224] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe[2224] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe[2224] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqsvc.exe[2356] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\mqsvc.exe[2356] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\mqsvc.exe[2356] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\tcpsvcs.exe[2400] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\tcpsvcs.exe[2400] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
GMER LOG PART 3 .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\Program Files\STOPzilla!\STOPzilla.exe[2416] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\Panda Software\Panda Internet Security 2007\apvxdwin.exe[2492] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\apvxdwin.exe[2492] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\apvxdwin.exe[2492] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\apvxdwin.exe[2492] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe[2712] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\Program Files\WinPortrait\wpctrl.exe[2820] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe[2828] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\mqtgsvc.exe[2840] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\mqtgsvc.exe[2840] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\svchost.exe[2880] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\svchost.exe[2880] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\svchost.exe[2880] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\svchost.exe[2880] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\svchost.exe[2880] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\svchost.exe[2880] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\Program Files\WinPortrait\floater.exe[2892] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\Program Files\WinPortrait\floater.exe[2892] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\Program Files\WinPortrait\floater.exe[2892] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\Program Files\WinPortrait\floater.exe[2892] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\Program Files\WinPortrait\floater.exe[2892] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\Program Files\WinPortrait\floater.exe[2892] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe[3028] ntdll.dll!NtCreateFile 77F7595E 5 Bytes CALL 7FFA2717 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe[3028] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe[3028] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe[3028] ntdll.dll!NtOpenFile 77F75DFB 5 Bytes CALL 7FFA2764 .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\rundll32.exe[3296] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ] .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A .text C:\WINDOWS\system32\rundll32.exe[3296] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778 .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ] .text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
GMER LOG PART 4 (FINAL) AND HIJACHTHIS LOG

.text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3352] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\ctfmon.exe[3352] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\Program Files\Logitech\Video\LogiTray.exe[3448] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVComS.exe[3780] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\LVComS.exe[3780] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateProcess 77F759F4 5 Bytes CALL 7FFA276B
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtCreateProcessEx 77F75A03 5 Bytes CALL 7FFA2778
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\soundman.exe[3924] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\soundman.exe[3924] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\soundman.exe[3924] OLE32.DLL!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\soundman.exe[3924] OLE32.DLL!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\soundman.exe[3924] OLE32.DLL!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\soundman.exe[3924] OLE32.DLL!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!LdrLoadDll 77F55669 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!LdrLoadDll + 4 77F5566D 2 Bytes [ 4A, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtClose 77F758AA 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtClose + 4 77F758AE 2 Bytes [ 4D, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtCreateFile 77F7595E 1 Byte [ FF ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtCreateFile + 2 77F75960 1 Byte [ 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtCreateFile + 4 77F75962 2 Bytes [ 6E, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtCreateKey 77F7599A 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtCreateKey + 4 77F7599E 2 Bytes [ 50, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDeleteFile 77F75AD5 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDeleteFile + 4 77F75AD9 2 Bytes [ 71, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDeleteKey 77F75AE4 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDeleteKey + 4 77F75AE8 2 Bytes [ 53, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDeleteValueKey 77F75B02 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDeleteValueKey + 4 77F75B06 2 Bytes [ 56, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDuplicateObject 77F75B2F 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtDuplicateObject + 4 77F75B33 2 Bytes [ 59, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtEnumerateKey 77F75B5C 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtEnumerateKey + 4 77F75B60 2 Bytes [ 5C, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtEnumerateValueKey 77F75B7A 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtEnumerateValueKey + 4 77F75B7E 2 Bytes [ 5F, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtOpenFile 77F75DFB 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtOpenFile + 4 77F75DFF 2 Bytes [ 74, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtQueryMultipleValueKey 77F7609E 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtQueryMultipleValueKey + 4 77F760A2 2 Bytes [ 62, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtQueryValueKey 77F7618E 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtQueryValueKey + 4 77F76192 2 Bytes [ 65, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtReadFile 77F761E8 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtReadFile + 4 77F761EC 2 Bytes [ 77, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtSetInformationFile 77F7644F 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtSetInformationFile + 4 77F76453 2 Bytes [ 7A, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtSetValueKey 77F765A8 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtSetValueKey + 4 77F765AC 2 Bytes [ 68, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtUnloadKey 77F76696 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtUnloadKey + 4 77F7669A 2 Bytes [ 6B, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtWriteFile 77F7673B 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ntdll.dll!NtWriteFile + 4 77F7673F 2 Bytes [ 7D, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!TerminateProcess 77E616B8 6 Bytes JMP 5F310F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!WriteProcessMemory 77E61A94 6 Bytes JMP 5F370F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!CopyFileExW 77E7035A 6 Bytes JMP 5F3A0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!MoveFileWithProgressW 77E713A2 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!MoveFileWithProgressW + 4 77E713A6 2 Bytes [ 44, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!CreateFileMappingW 77E7A47F 6 Bytes JMP 5F3D0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!MapViewOfFileEx 77E7B641 6 Bytes JMP 5F340F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!CreateRemoteThread 77E7BC9F 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!CreateRemoteThread + 4 77E7BCA3 2 Bytes [ 41, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!CreateProcessInternalW 77E8033A 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] kernel32.dll!CreateProcessInternalW + 4 77E8033E 2 Bytes [ 47, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!DispatchMessageW 77D43DEC 6 Bytes JMP 5FA90F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!TranslateMessage 77D43DFA 6 Bytes JMP 5F940F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!DispatchMessageA 77D44381 6 Bytes JMP 5F910F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!GetKeyState 77D46B2E 6 Bytes JMP 5FA00F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!BeginDeferWindowPos 77D47BB3 6 Bytes JMP 5F8E0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!CreateAcceleratorTableW 77D536DF 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!CreateAcceleratorTableW + 4 77D536E3 2 Bytes [ A4, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!GetAsyncKeyState 77D54E17 6 Bytes JMP 5F970F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!SetWindowsHookExA 77D55006 6 Bytes JMP 5F8B0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!SetWindowsHookExW 77D5506A 6 Bytes JMP 5FA60F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!AttachThreadInput 77D58218 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!AttachThreadInput + 4 77D5821C 2 Bytes [ 9B, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!GetKeyboardState 77D61F9B 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] USER32.dll!GetKeyboardState + 4 77D61F9F 2 Bytes [ 9E, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!CloseServiceHandle 77DD211E 6 Bytes JMP 5F100F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!OpenServiceW 77DD21F1 6 Bytes JMP 5F220F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!StartServiceA 77DDDF0E 6 Bytes JMP 5F250F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!OpenServiceA 77DE024F 6 Bytes JMP 5F1F0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!ControlService 77DE031F 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!StartServiceW 77DE0BC9 6 Bytes JMP 5F280F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!ChangeServiceConfigW 77DF7A75 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!ChangeServiceConfig2W 77DF7B2B 6 Bytes JMP 5F0D0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!CreateServiceW 77DF7B8A 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!LsaAddAccountRights 77E0FAE8 6 Bytes JMP 5F2B0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!LsaRemoveAccountRights 77E0FB66 6 Bytes JMP 5F2E0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!ChangeServiceConfigA 77E28920 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!ChangeServiceConfig2A 77E28A97 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!CreateServiceA 77E28B02 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ADVAPI32.dll!DeleteService 77E28C7F 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ole32.dll!CoCreateInstanceEx 771C212D 6 Bytes JMP 5F880F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ole32.dll!CoGetClassObject 771C48A9 6 Bytes JMP 5F850F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ole32.dll!CLSIDFromProgID 771EF3C3 6 Bytes JMP 5F820F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[4292] ole32.dll!CLSIDFromProgIDEx 771EF7DD 6 Bytes JMP 5F7F0F5A

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [BA13BFB4] xpdx.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F7752920] ShlDrv51.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [BA0FA98A] runtime2.sys
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE [F7752430] ShlDrv51.sys
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION [F77528D0] ShlDrv51.sys
Device \Driver\Modem \Device\000089 IRP_MJ_WRITE [F77E8494] COMFiltr.sys
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F7752430] ShlDrv51.sys
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F77528D0] ShlDrv51.sys

—- Services - GMER 1.0.12 —-

Service C:\WINDOWS\system32\drivers\runtime2.sys (*** hidden *** ) [SYSTEM] runtime2 <– ROOTKIT !!!

—- Registry - GMER 1.0.12 —-

Reg \Registry\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@ImagePath \SystemRoot\system32\drivers\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@DependOnGroup File System
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\runtime2@SDTEST6 SDTEST
Reg \Registry\MACHINE\SYSTEM\controlset002\control\SafeBoot\Minimal\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\controlset002\control\SafeBoot\Minimal\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\controlset002\control\SafeBoot\Network\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\controlset002\control\SafeBoot\Network\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@ImagePath \SystemRoot\system32\drivers\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@Type 1
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@Start 1
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@DependOnGroup File System
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@
Reg \Registry\MACHINE\SYSTEM\controlset002\Services\runtime2@SDTEST6 SDTEST
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\runtime2
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\runtime2@ImagePath \SystemRoot\system32\drivers\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\runtime2@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\runtime2@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\runtime2@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\runtime2@DependOnGroup File System
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\runtime2.sys@ Driver
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@ImagePath \SystemRoot\system32\drivers\runtime2.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@DependOnGroup File System
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\runtime2@SDTEST6 SDTEST

—- Files - GMER 1.0.12 —-

File C:\WINDOWS\system32\drivers\runtime2.sys <– ROOTKIT !!!

—- EOF - GMER 1.0.12 —-







Logfile of HijackThis v1.99.1
Scan saved at 16:01:01, on 31/05/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
c:\program files\panda software\panda internet security 2007\firewall\PSHOST.EXE
C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe
C:\Program Files\WinPortrait\floater.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\SRVLOAD.EXE
C:\WINDOWS\System32\LVComS.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ipmon] ipmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4A026B12-94F3-4D2F-A468-96AA55DE20A5} (NetCamPlayerWeb11g Control) - http://192.168.0.5/img/NetCamPlayerWeb11g.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173021502021
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180455924609
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Cepstral License Server - Cepstral, LLC - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda software\panda internet security 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe
Hi spierian,

There is an active rootkit on your machine, we will remove it using GMER:

Open GMER again, if it gives you a warning at program start about rootkit activity and asks if you want to run scan…say OK
If no warning….Check that the Rootkit tab is selected and click the Scan button - don't change any settings before you do so
Once the scan is complete, find this line:

Service C:\WINDOWS\system32\drivers\runtime2.sys (*** hidden *** ) [SYSTEM] runtime2 <– ROOTKIT !!!

Right-click the line and choose Delete the service
Then either allow GMER to reboot your system or close GMER and reboot it manually.

Then, run a new GMER scan, please do not use your computer while the scan is running, and post the log along with a new HijackThis log.
When I started GMER it detected this entry immediately, before asking about a scan. I got GMER to delete it but after rebooting and running GMER it was still there. I tried 3 times without success. Here is a Hijackthis log. Do you still want a GMER log?



Logfile of HijackThis v1.99.1
Scan saved at 09:04:50, on 01/06/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
c:\program files\panda software\panda internet security 2007\firewall\PSHOST.EXE
C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe
C:\Program Files\WinPortrait\floater.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\System32\LVComS.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\SRVLOAD.EXE
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\WebProxy.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\PavBckPT.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\Upgrader.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: H - {040FA520-78C6-41ce-81D0-9E733ABC1A29} - C:\WINDOWS\System32\comi.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ipmon] ipmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4A026B12-94F3-4D2F-A468-96AA55DE20A5} (NetCamPlayerWeb11g Control) - http://192.168.0.5/img/NetCamPlayerWeb11g.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173021502021
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180455924609
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Cepstral License Server - Cepstral, LLC - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda software\panda internet security 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\TPSrv.exe
That's surprising, could you please try once more, even if GMER gives you a rootkit warning do a rootkit scan anyway.
There are two similar lines in the GMER log, please check that you are choosing the line beginning with Service, and that you are choosing the Delete the service option.
Hi, How are you getting on? If the instructions are unclear or something isn't working, please let me know before proceeding.
Hi, the instructions were fine. The problem was that the symptoms kept changing. I decided to bite the bullet and completely rebuild both PCs. I deleted and re-formatted the affected partitions, re-installed XP, SP2 and all the updates. Then I had the slog of installing all my own apps. It's now pretty much complete and despite the time and effort I am very happy with the outcome. Thanks a lot for your help. It gave me comfort to know that somebody knew how to tackle this kind of thing!
Hi spierian,

Your machine was severely infected so I can understand your decision. Here are some tips to help you keep your machine clean:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

Along with antivirus and antispyware software, you should consider installing a Personal Firewall program. Even if you are behind a NAT router, I recommend you use firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, I recommend Sunbelt Software's Kerio or Zone Alarm:
http://www.sunbelt-software.com/Kerio
http://www.zonelabs.com/

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
If you install this, be sure to follow the DNS Client service instructions before doing so.

Spywareblaster is a free program which prevents the download and installation of Internet Explorer ActiveX based malware by immunizing your system against it. You can download Spywareblaster from here and a tutorial to help you get started is available here.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Find out more about how to prevent infection in the future:
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know you have read this, and if there are any further issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI