offline
- Pridružio: 21 Avg 2007
- Poruke: 56
|
Eve rezultati od GMER
____________________
GMER 1.0.13.12551 - gmer.net
Rootkit scan 2007-09-07 09:39:03
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwClose
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcessEx
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSymbolicLinkObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDuplicateObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwFlushKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwInitializeRegistry
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadDriver
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey2
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwNotifyChangeKey
SSDT kl1.sys ZwOpenFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryMultipleValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwReplaceKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwRestoreKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwResumeThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSaveKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetContextThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetSecurityObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSuspendThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSystemDebugControl
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwUnloadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwWriteVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[284]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[285]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[286]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[287]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[288]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[289]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[290]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[291]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[292]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[293]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[294]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[295]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[296]
Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.13 ----
.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804E9E14 5 Bytes JMP F4E47790 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EE54E 5 Bytes JMP F4E47C90 \??\C:\WINDOWS\system32\drivers\klif.sys
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified.
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[304] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[304] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[304] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\System32\svchost.exe[304] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\System32\svchost.exe[304] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\System32\svchost.exe[304] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\System32\svchost.exe[304] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[628] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[628] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[628] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\system32\svchost.exe[628] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\system32\svchost.exe[628] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\system32\svchost.exe[628] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\svchost.exe[628] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1040] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[1040] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\system32\spoolsv.exe[1040] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\system32\spoolsv.exe[1040] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\system32\spoolsv.exe[1040] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\spoolsv.exe[1040] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1140] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe[1168] USER32.dll!VRipOutput + FFFA5010 77D42A78 4 Bytes [ 70, 11, 7C, 00 ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Opera\Opera.exe[1504] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Opera\Opera.exe[1504] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Opera\Opera.exe[1504] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\Program Files\Opera\Opera.exe[1504] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\Program Files\Opera\Opera.exe[1504] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, EF, F4 ]
.text C:\Program Files\Opera\Opera.exe[1504] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\Program Files\Opera\Opera.exe[1504] advapi32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\Program Files\Opera\Opera.exe[1504] advapi32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1628] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1628] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\csrss.exe[1628] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\system32\csrss.exe[1628] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\system32\csrss.exe[1628] KERNEL32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\system32\csrss.exe[1628] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\csrss.exe[1628] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1652] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1652] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[1652] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\system32\winlogon.exe[1652] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\system32\winlogon.exe[1652] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\system32\winlogon.exe[1652] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\winlogon.exe[1652] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1696] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[1696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[1696] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\system32\services.exe[1696] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\system32\services.exe[1696] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\system32\services.exe[1696] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\services.exe[1696] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, EF, F4 ]
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] kernel32.dll!SetUnhandledExceptionFilter 7C810386 5 Bytes JMP 004DE392 C:\Program Files\MSN Messenger\msnmsgr.exe
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1760] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, EF, F4 ]
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ADVAPI32.DLL!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\Program Files\OpenVPN\bin\openvpn.exe[2024] ADVAPI32.DLL!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2336] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\Explorer.EXE[2336] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[2336] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\WINDOWS\Explorer.EXE[2336] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\WINDOWS\Explorer.EXE[2336] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, EF, F4 ]
.text C:\WINDOWS\Explorer.EXE[2336] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\WINDOWS\Explorer.EXE[2336] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\Explorer.EXE[2336] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!StrStrW + FFE2AEDD 7C9C42A8 4 Bytes [ F0, 00, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!StrStrW + FFE2AEE9 7C9C42B4 4 Bytes [ 60, 01, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!StrStrW + FFE2C555 7C9C5920 4 Bytes [ F0, 00, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!StrStrW + FFE2C651 7C9C5A1C 4 Bytes [ F0, 07, D6, 02 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!StrStrW + FFE2C66D 7C9C5A38 4 Bytes [ 60, 01, 4A, 01 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFree + 24F 7C9E2B50 4 Bytes [ 50, 0C, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFree + 6B7 7C9E2FB8 4 Bytes [ 10, 0E, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!SHLoadOLE + 5F 7C9E305C 4 Bytes [ 70, 0B, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!IsNetDrive + CDD 7C9EAD1C 4 Bytes [ 10, 07, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!IsNetDrive + D01 7C9EAD40 4 Bytes [ 10, 0E, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFindChild + 195 7C9EB96C 4 Bytes [ 10, 07, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFindChild + 133D 7C9ECB14 4 Bytes [ 90, 0A, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFindChild + 1355 7C9ECB2C 4 Bytes [ 10, 0E, D6, 02 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFindChild + 28C5 7C9EE09C 4 Bytes [ 80, 07, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ILFindChild + 2921 7C9EE0F8 4 Bytes [ F0, 07, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!SHCreateShellFolderView + 460E 7C9F4C7C 4 Bytes [ 60, 08, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!SHCreateShellFolderView + 462E 7C9F4C9C 4 Bytes [ C0, 05, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!SHCreateShellFolderView + 4666 7C9F4CD4 4 Bytes [ 50, 05, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!DllCanUnloadNow + 7F7 7CA01DB0 4 Bytes [ A0, 0D, D6, 02 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!SHGetMalloc + 340 7CA02324 4 Bytes [ 00, 0B, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!ShellExecuteExW + 220A 7CA0F808 4 Bytes [ C0, 0C, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!DragQueryFileAorW + 3A8F 7CA237A0 4 Bytes [ B0, 09, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!DragQueryFileAorW + 417F 7CA23E90 4 Bytes [ 60, 0F, 4A, 01 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!DragQueryFileAorW + 4257 7CA23F68 4 Bytes [ 90, 0A, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!DragQueryFileAorW + 42FF 7CA24010 4 Bytes [ 10, 00, D6, 02 ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!DragQueryFileAorW + 431F 7CA24030 4 Bytes [ 50, 0C, 43, 7D ]
.text ...
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!InternalExtractIconListA + 235F 7CA2B8A8 4 Bytes [ A0, 0D, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!InternalExtractIconListA + 241B 7CA2B964 4 Bytes [ 20, 0A, 43, 7D ]
.text C:\WINDOWS\Explorer.EXE[2336] SHELL32.dll!SHGetSetFolderCustomSettingsW + EE6 7CA2C9F4 4 Bytes [ F0, 0E, 43, 7D ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, EF, F4 ]
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ADVAPI32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\PC\Desktop\gmer\gmer.exe[2404] ADVAPI32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DAP\DAP.EXE[2828] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\DAP\DAP.EXE[2828] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\DAP\DAP.EXE[2828] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F200F5A
.text C:\Program Files\DAP\DAP.EXE[2828] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F1D0F5A
.text C:\Program Files\DAP\DAP.EXE[2828] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, EF, F4 ]
.text C:\Program Files\DAP\DAP.EXE[2828] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F230F5A
.text C:\Program Files\DAP\DAP.EXE[2828] advapi32.dll!RegSetValueExA 77DDEBE7 6 Bytes JMP 5F160F5A
.text C:\Program Files\DAP\DAP.EXE[2828] advapi32.dll!RegSetValueA 77DE6F49 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Winamp\winamp.exe[4028] ntdll.dll!Nt
|