Velký log z
GMERU
(první část, do jednoho příspěvku se nevešel):
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-09-28 12:59:52
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT sptd.sys ZwCreateKey [0xBA6DCB3A]
SSDT sptd.sys ZwEnumerateKey [0xBA6DCC7E]
SSDT sptd.sys ZwEnumerateValueKey [0xBA6DCFF6]
SSDT sptd.sys ZwOpenKey [0xBA6DCA18]
SSDT sptd.sys ZwQueryKey [0xBA6DD0C0]
SSDT sptd.sys ZwQueryValueKey [0xBA6DCF58]
SSDT sptd.sys ZwSetValueKey [0xBA6DD148]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB5BA79AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB5BA7958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB5BA796C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB5BA7A59]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB5BA7A85]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB5BA79EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB5BA7B1D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB5BA7930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB5BA7944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB5BA79BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB5BA7AC7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB5BA7A6F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xB5BA7B45]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xB5BA7B31]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB5BA7996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB5BA7982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB5BA7A19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xB5BA7B07]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB5BA7A00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB5BA79D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.14 ----
.text ntkrnlpa.exe!ZwYieldExecution 80503FC8 7 Bytes JMP B5BA79D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\sptd.sys Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
? C:\WINDOWS\System32\Drivers\SPTD0221.SYS Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
? Combo-Fix.sys Systém nemůže nalézt uvedený soubor. !
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 B92E04D0 16 Bytes [ BC, 0D, 5D, D1, B6, F9, 4F, ... ]
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 + 11 B92E04E1 31 Bytes [ F0, 2D, B9, F5, 92, 82, 8F, ... ]
? C:\WINDOWS\System32\Drivers\dtscsi.sys Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
? C:\ComboFix\catchme.sys Systém nemůže nalézt uvedenou cestu. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.14 ----
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 008A0FEF
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 008A0F85
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 008A0084
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 008A0073
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 008A0058
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 008A002C
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008A0F63
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 008A00AB
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008A00E1
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008A0F3E
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008A00FC
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 008A0047
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 008A000A
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 008A0F74
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 008A0FC0
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 008A001B
.text C:\WINDOWS\System32\svchost.exe[296] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 008A00BC
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00890047
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 0089007D
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 0089002C
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 0089001B
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 00890062
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 00890FC0
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 0089000A
.text C:\WINDOWS\System32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 00890FDB
.text C:\WINDOWS\System32\svchost.exe[296] WS2_32.dll!socket 71A93B91 5 Bytes JMP 007C000A
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00800FEF
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00800089
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00800F94
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00800FA5
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00800058
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0080002C
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00800F52
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0080009A
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00800F30
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008000BF
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00800F1F
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00800047
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00800F6F
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 0080001B
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00800FD4
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00800F41
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 007B001E
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 007B0F86
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 007B0FC3
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 007B0FD4
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 007B0043
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 007B0FA1
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 007B0FE5
.text C:\WINDOWS\system32\svchost.exe[416] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 007B0FB2
.text C:\WINDOWS\system32\svchost.exe[416] WS2_32.dll!socket 71A93B91 5 Bytes JMP 00780000
.text C:\WINDOWS\system32\svchost.exe[416] WININET.dll!InternetOpenW 771AAED5 5 Bytes JMP 00790FD4
.text C:\WINDOWS\system32\svchost.exe[416] WININET.dll!InternetOpenA 771B574E 5 Bytes JMP 00790FE5
.text C:\WINDOWS\system32\svchost.exe[416] WININET.dll!InternetOpenUrlA 771B5A01 5 Bytes JMP 00790000
.text C:\WINDOWS\system32\svchost.exe[416] WININET.dll!InternetOpenUrlW 771C5B4A 5 Bytes JMP 00790FAD
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 011E0000
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 011E00B1
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 011E008C
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 011E0FB2
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 011E0FC3
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 011E005B
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 011E0F90
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 011E0FA1
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 011E0F53
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 011E0F64
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 011E0F38
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 011E0FD4
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 011E001B
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 011E00C2
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 011E0FE5
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 011E0036
.text C:\WINDOWS\system32\svchost.exe[1068] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 011E0F7F
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 011D003D
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 011D0FB6
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 011D0022
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 011D0011
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 011D0FC7
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 011D0069
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 011D0000
.text C:\WINDOWS\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 011D004E
.text C:\WINDOWS\system32\svchost.exe[1068] WS2_32.dll!socket 71A93B91 5 Bytes JMP 011B0FEF
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00070F65
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070064
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00070053
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0007001B
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 0007009C
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00070F54
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00070F1E
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 000700B7
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00070EF9
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00070F94
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 0007007F
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00070FAF
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00070FCA
.text C:\WINDOWS\system32\services.exe[1356] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00070F39
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00060FC3
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 00060F8D
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 00060FDE
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 0006004A
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 0006002F
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 0006000A
.text C:\WINDOWS\system32\services.exe[1356] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 00060FA8
.text C:\WINDOWS\system32\services.exe[1356] WS2_32.dll!socket 71A93B91 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00FF006E
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00FF0F83
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00FF0F94
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00FF0051
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00FF0FB9
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00FF0F30
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00FF0F41
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00FF00A4
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00FF0089
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00FF0EF0
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00FF0036
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00FF0FE5
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00FF0F5E
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00FF001B
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00FF0FD4
.text C:\WINDOWS\system32\lsass.exe[1368] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00FF0F15
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00FE0022
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 00FE0047
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 00FE0F8A
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 00FE0FAF
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\lsass.exe[1368] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\lsass.exe[1368] WS2_32.dll!socket 71A93B91 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00BE0089
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00BE0F94
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00BE006C
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00BE005B
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00BE0039
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00BE0F72
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00BE0F83
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00BE0F35
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00BE0F46
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00BE00E9
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00BE004A
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00BE00AE
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00BE0FC3
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00BE0FD4
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00BE0F61
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00BD0FD4
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 00BD0087
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 00BD001B
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 00BD006C
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 00BD005B
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 00BD0000
.text C:\WINDOWS\system32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 00BD0040
.text C:\WINDOWS\system32\svchost.exe[1544] WS2_32.dll!socket 71A93B91 5 Bytes JMP 00BB000A
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00A50FEF
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00A5007F
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00A5006E
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00A5005D
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00A50036
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00A50F9E
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00A50F52
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00A5009A
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A50F26
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A50F41
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00A50F0B
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00A5001B
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00A50FDE
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00A50F79
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00A50FB9
.text C:\WINDOWS\system32\svchost.exe[1604] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00A500BF
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00A40FB9
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 00A40F9E
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 00A40FCA
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 00A40000
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 00A4005B
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 00A40036
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 00A40FEF
.text C:\WINDOWS\system32\svchost.exe[1604] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 00A40025
.text C:\WINDOWS\system32\svchost.exe[1604] WS2_32.dll!socket 71A93B91 5 Bytes JMP 00A20FEF
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1808] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1808] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 03750FEF
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 03750040
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 03750025
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 03750F4B
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 03750F68
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 03750F94
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 03750F30
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0375006C
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 03750093
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 03750F04
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 037500B8
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 03750F79
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 03750000
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 0375005B
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 03750FB9
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 03750FCA
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 03750F1F
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 0374005B
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 03740FE5
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 03740036
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 0374001B
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 037400A2
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 03740091
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 03740000
.text C:\WINDOWS\System32\svchost.exe[1856] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 03740076
.text C:\WINDOWS\System32\svchost.exe[1856] WS2_32.dll!socket 71A93B91 5 Bytes JMP 02D30FEF
.text C:\WINDOWS\System32\svchost.exe[1856] WININET.dll!InternetOpenW 771AAED5 5 Bytes JMP 02DD0FDE
.text C:\WINDOWS\System32\svchost.exe[1856] WININET.dll!InternetOpenA 771B574E 5 Bytes JMP 02DD0FEF
.text C:\WINDOWS\System32\svchost.exe[1856] WININET.dll!InternetOpenUrlA 771B5A01 5 Bytes JMP 02DD0FCD
.text C:\WINDOWS\System32\svchost.exe[1856] WININET.dll!InternetOpenUrlW 771C5B4A 5 Bytes JMP 02DD0FB0
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A004C
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F57
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0F72
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0F83
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A0025
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0082
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A0F3A
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A00AE
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F15
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00BF
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0F94
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0FDE
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0071
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FB9
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0014
.text C:\WINDOWS\explorer.exe[2796] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A0093
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 002D002F
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 002D0FA8
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 002D0FD4
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 002D0FE5
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 002D0065
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 002D004A
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 002D0000
.text C:\WINDOWS\explorer.exe[2796] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 002D0FC3
.text C:\WINDOWS\explorer.exe[2796] WININET.dll!InternetOpenW 771AAED5 5 Bytes JMP 00300000
.text C:\WINDOWS\explorer.exe[2796] WININET.dll!InternetOpenA 771B574E 5 Bytes JMP 00300FE5
.text C:\WINDOWS\explorer.exe[2796] WININET.dll!InternetOpenUrlA 771B5A01 5 Bytes JMP 0030001D
.text C:\WINDOWS\explorer.exe[2796] WININET.dll!InternetOpenUrlW 771C5B4A 5 Bytes JMP 00300038
.text C:\WINDOWS\explorer.exe[2796] WS2_32.dll!socket 71A93B91 5 Bytes JMP 00E7000A
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0000
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F7C
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F8D
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0FA8
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0FB9
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A0040
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A00C4
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A00A7
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0F46
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F57
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00F0
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0051
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0FE5
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A008C
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FD4
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A001B
.text C:\Program Files\Messenger\msmsgs.exe[3984] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A00DF
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 002E0FE5
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 002E0098
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 002E0040
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 002E0025
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 002E007D
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 002E006C
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 002E000A
.text C:\Program Files\Messenger\msmsgs.exe[3984] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 002E0051
.text C:\Program Files\Messenger\msmsgs.exe[3984] WS2_32.dll!socket 71A93B91 5 Bytes JMP 002F0FEF
.text C:\Program Files\Messenger\msmsgs.exe[3984] WININET.dll!InternetOpenW 771AAED5 5 Bytes JMP 0030001B
.text C:\Program Files\Messenger\msmsgs.exe[3984] WININET.dll!InternetOpenA 771B574E 5 Bytes JMP 00300000
.text C:\Program Files\Messenger\msmsgs.exe[3984] WININET.dll!InternetOpenUrlA 771B5A01 5 Bytes JMP 00300FE5
.text C:\Program Files\Messenger\msmsgs.exe[3984] WININET.dll!InternetOpenUrlW 771C5B4A 5 Bytes JMP 00300038
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6D8A32] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6D8B6E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6D8AF6] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6D96CC] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6D95A2] sptd.sys