This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] DDABC.DLL

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi John,

Nicely done, that was to have been my next suggestion. :D

OK, looking better still some work to do.

Run a scan with HJT and when finished check the following items (if found).

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize


Now close all open windows and click Fix Checked to remove them.

This is not a malicious process, it's just that the file got infected and was unable to be restored by Combofix, so the entry points to nothing. It was not an essential process, so should not impact anything by not being there.

It belongs to nVidia, so you can re-install that software if you feel you really need it.

http://www.castlecops.com/s2547-NvCplDaemon.html

In a similar fashion, Site Advisor has also been damaged, Uninstall and re-install the programme to repair it.

OK, couple of files found by Kaspersky that need taking care of.

Download OTMoveIt2 by Old Timer and save it to your Desktop.
  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080126-221713-819.dll
C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080127-094727-308.dll
  • Return to OTMoveIt2, right click in the Paste Standard List of Files/Folders to Move window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTMoveIt2

Note:
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
  • If you are asked to reboot the machine choose Yes.
  • After the reboot, open Notepad
    • Click Start > Run type Notepad into the Open: box then click OK
    • Next click File > Open type *.log into the File Name box then Open.
    • Navigate to the C:\_OTMoveIt\MovedFiles folder and open the newest .log file present.
  • Copy/Paste the contents back here please.

Next

I'd like to look a little deeper into your computer, I'm not happy with the blocking of Combofix, the infection that does this is often concealed by a Rootkit, so I'd like to scan your computer to check if that is the case.

Download GMER and unzip it to your Desktop. (It will create a folder GMER)

Alternate Download Site

  • Disconnect from the Internet, and close all running programmes.
  • There is a small chance this programme may crash your computer, so save any work you have open.
  • Open the GMER folder, and double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at programme start about rootkit activity and asks if you want to run a scan ….. click OK.
  • If no warning:
    • Click Rootkit tab.
    • Ensure that All the boxes to the right of the program are checked except Show All.
    • Click Scan.
  • Do not use your computer while the scan is running.
  • Once scan is finished click Copy.
    • Click Start > Run then type Notepad.exe then click OK.
    • This will open a Notepad file.
    • Hit Ctrl+V to paste log into it.
    • Save the log to your Desktop.
  • Reconnect to internet and post the log please.

Summary of the logs I need from you in your next post:
  • OTMoveIt
  • GMER


Please post each log separately to prevent them being cut off by the forum post size limiter.

Also please let me know how your computer is behaving now.
From OTMoveIt2: DllUnregisterServer procedure not found in C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080126-221713-819.dll C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080126-221713-819.dll NOT unregistered. C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080126-221713-819.dll moved successfully. DllUnregisterServer procedure not found in C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080127-094727-308.dll C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080127-094727-308.dll NOT unregistered. C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080127-094727-308.dll moved successfully. OTMoveIt2 v1.0.17 log created on 01312008_202724
Computer seems OK, I haven't seen any popups since a couple of steps ago.
My Local Disc (C:) icon is still a red delete X.
GMER Log:
GMER 1.0.14.14116 - http://www.gmer.net
Rootkit scan 2008-01-31 20:37:29
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xF2ACA6DC]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xF2ACAC9C]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwTerminateProcess [0xF2AC9C5C]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xF2AC9374]

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF2748978]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xF2748A0F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF2748A23]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF2748A4F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF2748ABD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF2748AA7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF27489B8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF2748AE9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xF27489FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF2748900]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF2748914]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF274898C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF2748B25]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF2748A91]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF2748A7B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF2748A39]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF2748B11]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF2748AFD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF2748964]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF2748950]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF2748A65]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF2748AD3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF27489CE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF27489A2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.14 —-

.text ntoskrnl.exe!ZwYieldExecution 804F8B8D 7 Bytes JMP F27489A6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80567CFB 5 Bytes JMP F27489FF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 8056B103 7 Bytes JMP F2748A7F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056BD4D 5 Bytes JMP F2748954 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 8056E7A9 5 Bytes JMP F2748A13 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 8056EBB9 7 Bytes JMP F2748B29 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 8056EEB0 7 Bytes JMP F2748AC1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056FBF8 5 Bytes JMP F274897C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 80571EF1 5 Bytes JMP F27489D2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057236C 7 Bytes JMP F27489BC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 80572D06 5 Bytes JMP F2748904 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 805730B5 7 Bytes JMP F2748990 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 80573C8D 7 Bytes JMP F2748A69 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 8057FB78 7 Bytes JMP F2748AAB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058C806 5 Bytes JMP F2748918 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 80590E16 5 Bytes JMP F2748AED \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80593AAC 7 Bytes JMP F2748A53 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 80595136 7 Bytes JMP F2748A27 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062C403 5 Bytes JMP F2748968 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8064C042 5 Bytes JMP F2748B01 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 8064C317 7 Bytes JMP F2748AD7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 8064CBE4 7 Bytes JMP F2748A95 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064D029 7 Bytes JMP F2748A3D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8064D51E 5 Bytes JMP F2748B15 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.14 —-

.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[212] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Google\Google Updater\GoogleUpdater.exe[364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\DOCUME~1\JOHNKO~1\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[372] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\Spyware Doctor\swdsvc.exe[444] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ 47, B3, C5, 83 ]
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00900FEF
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00900F88
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0090007D
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0090006C
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00900FAF
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00900047
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009000BF
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009000A2
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 009000EB
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00900F52
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00900F37
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00900FC0
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00900014
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00900F77
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00900036
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00900025
.text C:\Program Files\Messenger\msmsgs.exe[488] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 009000DA
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008E0FCA
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008E0F9E
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008E0025
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008E000A
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008E005B
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008E0FB9
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008E0FEF
.text C:\Program Files\Messenger\msmsgs.exe[488] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008E0036
.text C:\Program Files\Messenger\msmsgs.exe[488] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 008B0000
.text C:\Program Files\Messenger\msmsgs.exe[488] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 008B0025
.text C:\Program Files\Messenger\msmsgs.exe[488] WININET.dll!InternetOpenW 771BAF0D 1 Byte [ E9 ]
.text C:\Program Files\Messenger\msmsgs.exe[488] WININET.dll!InternetOpenW + 2 771BAF0F 3 Bytes [ 50, 70, 89 ]
.text C:\Program Files\Messenger\msmsgs.exe[488] WININET.dll!InternetOpenA 771C579E 5 Bytes JMP 008C0000
.text C:\Program Files\Messenger\msmsgs.exe[488] WININET.dll!InternetOpenUrlA 771C5A51 5 Bytes JMP 008C0022
.text C:\Program Files\Messenger\msmsgs.exe[488] WININET.dll!InternetOpenUrlW 771D5B62 5 Bytes JMP 008C0FCF
.text C:\WINDOWS\system32\csrss.exe[600] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[624] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[624] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[624] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[624] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[624] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[624] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[624] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateFileA 7C801A24 3 Bytes JMP 010C0FEF
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateFileA + 4 7C801A28 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!VirtualProtectEx 7C801A5D 3 Bytes JMP 010C0085
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!VirtualProtectEx + 4 7C801A61 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!VirtualProtect 7C801AD0 3 Bytes JMP 010C0F86
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!VirtualProtect + 4 7C801AD4 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 010C0F97
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryExA 7C801D4F 3 Bytes JMP 010C004A
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryExA + 4 7C801D53 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryA 7C801D77 3 Bytes JMP 010C002F
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryA + 4 7C801D7B 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!GetStartupInfoW 7C801E50 3 Bytes JMP 010C0F5A
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!GetStartupInfoW + 4 7C801E54 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 010C0F6B
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateProcessW 7C802332 3 Bytes JMP 010C00CE
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateProcessW + 4 7C802336 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateProcessA 7C802367 3 Bytes JMP 010C00BD
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateProcessA + 4 7C80236B 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!GetProcAddress 7C80ADA0 3 Bytes JMP 010C00E9
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!GetProcAddress + 4 7C80ADA4 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryW 7C80AE4B 3 Bytes JMP 010C0FA8
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!LoadLibraryW + 4 7C80AE4F 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateFileW 7C810760 3 Bytes JMP 010C0FDE
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateFileW + 4 7C810764 1 Byte [ 84 ]
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 010C0096
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 010C0FC3
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 010C0014
.text C:\WINDOWS\system32\services.exe[668] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 010C0F49
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 010B0FE5
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 010B0098
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 010B0036
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 010B001B
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 010B007D
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 010B0062
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 010B0000
.text C:\WINDOWS\system32\services.exe[668] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 010B0051
.text C:\WINDOWS\system32\services.exe[668] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B60000
.text C:\WINDOWS\system32\services.exe[668] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00B60FDB
.text C:\WINDOWS\system32\lsass.exe[680] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[680] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[680] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[680] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\lsass.exe[680] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[680] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E80000
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E800B5
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E80FC0
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E80FD1
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E8008E
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E80062
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E80F8A
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E80F9B
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E80F5E
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E800F7
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00E80108
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00E80073
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00E8001B
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00E800C6
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00E80051
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00E80036
.text C:\WINDOWS\system32\lsass.exe[680] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00E80F79
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00E70FB9
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00E70051
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00E70FCA
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00E70000
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00E70F94
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00E70036
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00E70FE5
.text C:\WINDOWS\system32\lsass.exe[680] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00E70025
.text C:\WINDOWS\system32\lsass.exe[680] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00E5000A
.text C:\WINDOWS\system32\lsass.exe[680] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00E50FE5
.text C:\WINDOWS\system32\svchost.exe[828] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[828] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[828] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[828] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[828] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[828] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 007C0FEF
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 007C0F5E
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 007C0F83
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 007C005D
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 007C0F9E
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 007C0FC3
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 007C0F2D
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 007C007F
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007C0EF0
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 007C0F01
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007C0ED5
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 007C0040
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 007C000A
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 007C006E
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 007C0FD4
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 007C0025
.text C:\WINDOWS\system32\svchost.exe[828] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 007C0F1C
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 007B0025
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 007B0F9E
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 007B0FD4
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 007B000A
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 007B005B
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 007B0FB9
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 007B0FEF
.text C:\WINDOWS\system32\svchost.exe[828] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 007B0040
.text C:\WINDOWS\system32\svchost.exe[828] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00790000
.text C:\WINDOWS\system32\svchost.exe[828] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00790011
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 008F000A
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 008F0071
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 008F0F7C
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 008F0056
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 008F0F97
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 008F0FC3
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008F0F55
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 008F009D
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008F00B8
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008F0F29
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008F0F04
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 008F0FA8
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 008F0FEF
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 008F008C
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 008F0FDE
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 008F002F
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 008F0F3A
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008E0FBC
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008E0F72
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008E0FCD
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008E0FDE
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008E0F8D
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008E002F
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008E0FEF
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008E001E
.text C:\WINDOWS\system32\svchost.exe[908] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 008C0FE5
.text C:\WINDOWS\system32\svchost.exe[908] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 008C0FD4
.text C:\WINDOWS\System32\svchost.exe[956] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[956] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[956] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[956] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\System32\svchost.exe[956] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[956] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01A4000A
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01A40F8A
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01A40FA5
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01A40FB6
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01A40073
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01A40FDB
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01A40090
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 01A40F54
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01A40F01
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01A40F12
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 01A400BF
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 01A40062
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 01A4001B
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 01A40F6F
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 01A40051
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 01A40040
.text C:\WINDOWS\System32\svchost.exe[956] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 01A40F23
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 01A30FC0
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 01A30F8A
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 01A30FDB
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 01A30011
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 01A30F9B
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 01A30047
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 01A30000
.text C:\WINDOWS\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 01A3002C
.text C:\WINDOWS\System32\svchost.exe[956] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01A00000
.text C:\WINDOWS\System32\svchost.exe[956] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 01A00FE5
.text C:\WINDOWS\System32\svchost.exe[956] WININET.dll!InternetOpenW 771BAF0D 5 Bytes JMP 01A10FE5
.text C:\WINDOWS\System32\svchost.exe[956] WININET.dll!InternetOpenA 771C579E 5 Bytes JMP 01A10000
.text C:\WINDOWS\System32\svchost.exe[956] WININET.dll!InternetOpenUrlA 771C5A51 5 Bytes JMP 01A10FD4
.text C:\WINDOWS\System32\svchost.exe[956] WININET.dll!InternetOpenUrlW 771D5B62 5 Bytes JMP 01A10FC3
.text C:\WINDOWS\System32\svchost.exe[1248] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1248] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1248] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1248] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1248] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1248] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00660FEF
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00660F4B
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00660040
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00660F66
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00660025
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00660F8D
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00660EF8
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00660F13
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00660EE7
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00660076
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00660ECC
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00660014
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00660FD4
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00660F30
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00660FA8
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00660FC3
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 0066005B
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00650025
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00650F94
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00650FD4
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00650000
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00650FA5
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00650047
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00650FE5
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00650036
.text C:\WINDOWS\System32\svchost.exe[1248] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00630FEF
.text C:\WINDOWS\System32\svchost.exe[1248] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00630FDE
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00810000
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00810073
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00810062
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00810F8A
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00810047
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0081002C
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00810F59
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00810095
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008100D7
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008100C6
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00810F23
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00810FA5
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00810011
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00810084
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00810FC0
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00810FDB
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00810F3E
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00710FCA
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00710F54
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0071001B
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00710000
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00710F6F
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00710F8A
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00710FE5
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00710FAF
.text C:\WINDOWS\System32\svchost.exe[1320] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 006E0FE5
.text C:\WINDOWS\System32\svchost.exe[1320] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 006E0FD4
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenW 771BAF0D 5 Bytes JMP 006F0FE5
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenA 771C579E 5 Bytes JMP 006F0000
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenUrlA 771C5A51 5 Bytes JMP 006F001D
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenUrlW 771D5B62 5 Bytes JMP 006F0FCA
.text C:\WINDOWS\Explorer.EXE[1324] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1324] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\Explorer.EXE[1324] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1324] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\Explorer.EXE[1324] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1324] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C70FEF
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C70F72
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C70067
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C7004C
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C7002F
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C7001E
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C70F3A
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C70F4B
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C700B8
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C70F1F
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00C70F04
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00C70F97
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00C70FD4
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00C70082
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00C70FB2
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00C70FC3
.text C:\WINDOWS\Explorer.EXE[1324] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00C7009D
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00B90025
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00B90FB9
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00B90014
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00B90FD4
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00B90076
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00B9005B
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00B90FEF
.text C:\WINDOWS\Explorer.EXE[1324] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00B9004A
.text C:\WINDOWS\Explorer.EXE[1324] WININET.dll!InternetOpenW 771BAF0D 5 Bytes JMP 00B6001B
.text C:\WINDOWS\Explorer.EXE[1324] WININET.dll!InternetOpenA 771C579E 5 Bytes JMP 00B60000
.text C:\WINDOWS\Explorer.EXE[1324] WININET.dll!InternetOpenUrlA 771C5A51 5 Bytes JMP 00B60036
.text C:\WINDOWS\Explorer.EXE[1324] WININET.dll!InternetOpenUrlW 771D5B62 5 Bytes JMP 00B60FEF
.text C:\WINDOWS\Explorer.EXE[1324] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B50FE5
.text C:\WINDOWS\Explorer.EXE[1324] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00B50000
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1612] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1660] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1728] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1728] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1748] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[680] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[828] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[908] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[956] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1248] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\Explorer.EXE[1324] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000

—- Devices - GMER 1.0.14 —-

AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- EOF - GMER 1.0.14 —-
Post 1 of 2

OK, as far as I can see you're clean of infection. Nothing in your GMER scan other than the protection systems fom McAfee and PCTools (Spyware Doctor) that I'd have expected to be there.

Not sure what caused your C:\ drive icon to change, I'll have to ask around on that one.

OK, lets do a little tidying up.

Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately. Besides they're updated regularly so won't be of any use against future infections
  • Double click OTMoveIt2.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTMoveIt will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTMoveIt
  • Now delete OTMoveIt2.exe (if still present).

Below are a series of recommendations which will help you keep more secure online.

Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.

THESE STEPS ARE VERY IMPORTANT

Lets reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to clean the restore points.
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot.
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.
  • NOTE: only do this once, NOT on a regular basis.

Updating Windows and Internet Explorer
It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.

Use a "secure" browser
Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.

The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.

  • WinPatrol by BillPStudios is a programme that monitors your computer and notifies you if there are any unauthorised changes made to it. It gives you the option to allow or forbid the changes, thus guarding you against Malware installations. I consider this one a must have.

    If you find you like it, you can get a lifetime upgrade to the Plus version for a small one time fee.
  • SpywareBlaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
  • IE Spyad
    It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
  • Hosts file:
  • Make sure you read the instructions on how to install the hosts file, here.

    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
  • If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Use an Anti Virus Software - It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - LIST of free Anti virus programs
  • Use a Firewall - I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    See here to choose one.
  • Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.

Here's links to a few articles which are well worth reading

Finally

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Vundo……. (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to government or government agencies that something will get done.



I'll get back to you within the next couple of days if I can find anything about the Drive icon.
Post 2 of 2

OK, think I've got a solution to your Drive Icon problem.

First

Create a System Restore Point

  • Click Start > Run
  • Copy/Paste C:\Windows\System32\Restore\rstrui.exe into the Open: box.
  • Click OK.
  • This will open the System Restore window.
  • Click on Create a Restore Point then click Next.
  • Enter Restore from Reg Changes to the description box, then click Create.
  • A new Restore Point will be created, click Close to exit.

Next

  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons]
  • Click Format and ensure Wordwrap is unchecked.
  • Save as RegFix.reg
  • Save as file type All Files or it won't work.
  • Now double click on RegFix.reg to run it.
  • You will be prompted to allow it to merge with the Registry. Allow it please.

Let me know if that fixed things.
Gary, Thank you so much for all your help and patience. Everything seems to be working fine now. I'm going to go over all your additional suggestions this weekend. –John
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI