![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: PC läuft sehr langsam, svchost.exe lastet das System extrem ausWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #10 |
![]() | PC läuft sehr langsam, svchost.exe lastet das System extrem aus Hallo cosinus, GMER ist beim 2. Mal gelaufen. Die osam.exe wird sofort von McAfee als Trojaner gelöscht. Wenn ich McAfee abschalte beendet OSAM den Scan nicht. Das Ergebnis des Remover darunter Grüße intrus Hier der GMER Log-File: {\rtf1\ansi\ansicpg1252\deff0\deflang1031{\fonttbl{\f0\fswiss\fcharset0 Arial;}} {\*\generator Msftedit 5.41.21.2509;}\viewkind4\uc1\pard\f0\fs20 GMER 1.0.15.15281 - hxxp://www.gmer.net\par Rootkit scan 2010-08-31 21:08:38\par Windows 6.0.6002 Service Pack 2\par Running: 8qhdetxd.exe; Driver: C:\\Users\\***\\AppData\\Local\\Temp\\ufryrpod.sys\par \par \par ---- System - GMER 1.0.15 ----\par \par Code \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x88434D88]\par Code \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x88434DB2]\par Code \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x88434D9E]\par Code \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x88434D74]\par Code \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection\par \par ---- Kernel code sections - GMER 1.0.15 ----\par \par .text ntoskrnl.exe!ZwYieldExecution 82879C0E 5 Bytes JMP 88434D78 \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)\par PAGE ntoskrnl.exe!ZwUnmapViewOfSection 82A50510 5 Bytes JMP 88434DA2 \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)\par PAGE ntoskrnl.exe!NtMapViewOfSection 82A50899 7 Bytes JMP 88434D8C \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)\par PAGE ntoskrnl.exe!ZwTerminateProcess 82A6004F 5 Bytes JMP 88434DB6 \\SystemRoot\\system32\\drivers\\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)\par .text C:\\Windows\\system32\\DRIVERS\\nvlddmkm.sys section is writeable [0x8CC0F340, 0x3448B7, 0xE8000020]\par \par ---- User code sections - GMER 1.0.15 ----\par \par .text C:\\Windows\\system32\\svchost.exe[308] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00240FE5 \par .text C:\\Windows\\system32\\svchost.exe[308] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00240000 \par .text C:\\Windows\\system32\\svchost.exe[308] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00240FCA \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 002200A7 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00220F61 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 002200E7 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 002200D6 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00220060 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 0022000A \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00220FAF \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 0022008C \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00220F7C \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00220F9E \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00220F8D \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00220025 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00220071 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 00220F35 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00220FD4 \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 00220FEF \par .text C:\\Windows\\system32\\svchost.exe[308] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 00220F50 \par .text C:\\Windows\\system32\\svchost.exe[308] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00720042 \par .text C:\\Windows\\system32\\svchost.exe[308] msvcrt.dll!system 77C6804B 5 Bytes JMP 00720027 \par .text C:\\Windows\\system32\\svchost.exe[308] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 00720FC8 \par .text C:\\Windows\\system32\\svchost.exe[308] msvcrt.dll!_open 77C6D106 5 Bytes JMP 0072000C \par .text C:\\Windows\\system32\\svchost.exe[308] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 00720FB7 \par .text C:\\Windows\\system32\\svchost.exe[308] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00720FEF \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00230F97 \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 00230FBC \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00230FEF \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00230039 \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 00230F86 \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 0023001E \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00230FDE \par .text C:\\Windows\\system32\\svchost.exe[308] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 00230FCD \par .text C:\\Windows\\system32\\svchost.exe[308] WS2_32.dll!socket 769936D1 3 Bytes JMP 00250000 \par .text C:\\Windows\\system32\\svchost.exe[308] WS2_32.dll!socket + 4 769936D5 1 Byte [89]\par .text C:\\Windows\\Explorer.EXE[684] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 03FD000A \par .text C:\\Windows\\Explorer.EXE[684] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 03FD0FEF \par .text C:\\Windows\\Explorer.EXE[684] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 03FD001B \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 01CD00E2 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 01CD0F9C \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 01CD0F55 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 01CD0F70 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 01CD00AC \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 01CD0040 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 01CD0051 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 01CD0FB7 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 01CD0091 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 01CD0FD4 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 01CD0080 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 01CD0FE5 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 01CD00C7 \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 01CD0F3A \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 01CD001B \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 01CD000A \par .text C:\\Windows\\Explorer.EXE[684] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 01CD0F81 \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 01CF0039 \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 01CF0FB2 \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 01CF0FEF \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 01CF0F97 \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 01CF004A \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 01CF0FCD \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 01CF0FDE \par .text C:\\Windows\\Explorer.EXE[684] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 01CF001E \par .text C:\\Windows\\Explorer.EXE[684] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 03FC003F \par .text C:\\Windows\\Explorer.EXE[684] msvcrt.dll!system 77C6804B 5 Bytes JMP 03FC0FBE \par .text C:\\Windows\\Explorer.EXE[684] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 03FC001D \par .text C:\\Windows\\Explorer.EXE[684] msvcrt.dll!_open 77C6D106 5 Bytes JMP 03FC0000 \par .text C:\\Windows\\Explorer.EXE[684] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 03FC002E \par .text C:\\Windows\\Explorer.EXE[684] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 03FC0FE3 \par .text C:\\Windows\\Explorer.EXE[684] WS2_32.dll!socket 769936D1 5 Bytes JMP 01CC0000 \par .text C:\\Windows\\Explorer.EXE[684] WININET.dll!InternetOpenA 76ACD690 5 Bytes JMP 01CE000A \par .text C:\\Windows\\Explorer.EXE[684] WININET.dll!InternetOpenW 76ACDB09 5 Bytes JMP 01CE0025 \par .text C:\\Windows\\Explorer.EXE[684] WININET.dll!InternetOpenUrlA 76ACF3A4 5 Bytes JMP 01CE0FEF \par .text C:\\Windows\\Explorer.EXE[684] WININET.dll!InternetOpenUrlW 76B16DDF 5 Bytes JMP 01CE0FCA \par .text C:\\Windows\\system32\\services.exe[820] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 0019000A \par .text C:\\Windows\\system32\\services.exe[820] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00190036 \par .text C:\\Windows\\system32\\services.exe[820] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00190025 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00180F4D \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00180F68 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00180F32 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 001800BF \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00180F8D \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00180025 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00180040 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 0018009D \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00180F9E \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00180FCA \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00180FAF \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 0018005B \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00180082 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 00180F17 \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00180FEF \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 0018000A \par .text C:\\Windows\\system32\\services.exe[820] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 001800AE \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 001B0FBC \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 001B0FCD \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 001B0000 \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 001B0054 \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 001B006F \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 001B0FDE \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 001B0FEF \par .text C:\\Windows\\system32\\services.exe[820] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 001B002F \par .text C:\\Windows\\system32\\services.exe[820] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00310FE5 \par .text C:\\Windows\\system32\\services.exe[820] msvcrt.dll!system 77C6804B 5 Bytes JMP 00310070 \par .text C:\\Windows\\system32\\services.exe[820] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 0031003A \par .text C:\\Windows\\system32\\services.exe[820] msvcrt.dll!_open 77C6D106 5 Bytes JMP 0031000C \par .text C:\\Windows\\system32\\services.exe[820] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 00310055 \par .text C:\\Windows\\system32\\services.exe[820] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00310029 \par .text C:\\Windows\\system32\\services.exe[820] WS2_32.dll!socket 769936D1 5 Bytes JMP 001A0000 \par .text C:\\Windows\\system32\\lsass.exe[948] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 000A0FE5 \par .text C:\\Windows\\system32\\lsass.exe[948] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 000A0FC0 \par .text C:\\Windows\\system32\\lsass.exe[948] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 000A0000 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00080F6D \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00080F7E \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00080F26 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 00080F37 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 000800A2 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00080036 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00080FDB \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 000800B3 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00080087 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 0008006C \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00080FCA \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00080051 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00080FAD \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 000800D8 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00080025 \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 0008000A \par .text C:\\Windows\\system32\\lsass.exe[948] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 00080F52 \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00840F79 \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 00840FAF \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00840000 \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00840F9E \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 00840F68 \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 0084001B \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00840FE5 \par .text C:\\Windows\\system32\\lsass.exe[948] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 00840FCA \par .text C:\\Windows\\system32\\lsass.exe[948] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00850FA8 \par .text C:\\Windows\\system32\\lsass.exe[948] msvcrt.dll!system 77C6804B 5 Bytes JMP 00850FB9 \par .text C:\\Windows\\system32\\lsass.exe[948] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 00850FD4 \par .text C:\\Windows\\system32\\lsass.exe[948] msvcrt.dll!_open 77C6D106 5 Bytes JMP 00850FEF \par .text C:\\Windows\\system32\\lsass.exe[948] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 00850029 \par .text C:\\Windows\\system32\\lsass.exe[948] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00850018 \par .text C:\\Windows\\system32\\lsass.exe[948] WS2_32.dll!socket 769936D1 5 Bytes JMP 00830FEF \par .text C:\\Windows\\system32\\svchost.exe[1136] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 008A0000 \par .text C:\\Windows\\system32\\svchost.exe[1136] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 008A0FE5 \par .text C:\\Windows\\system32\\svchost.exe[1136] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 008A001B \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 002A0F31 \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 002A0F4C \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 002A0F05 \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 002A0F16 \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 002A0F5D \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 002A0FCD \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 002A0FBC \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreatePipe 769E8E6E 3 Bytes JMP 002A0077 \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreatePipe + 4 769E8E72 1 Byte [89]\par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 002A0F6E \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryW 769E9362 3 Bytes JMP 002A0F90 \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryW + 4 769E9366 1 Byte [89]\par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryExA 769E94B4 3 Bytes JMP 002A0F7F \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryExA + 4 769E94B8 1 Byte [89]\par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryA 769E94DC 3 Bytes JMP 002A0FAB \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!LoadLibraryA + 4 769E94E0 1 Byte [89]\par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!VirtualProtectEx 769EDBDA 3 Bytes JMP 002A005C \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!VirtualProtectEx + 4 769EDBDE 1 Byte [89]\par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 002A00B7 \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 002A0FDE \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 002A0FEF \par .text C:\\Windows\\system32\\svchost.exe[1136] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 002A0092 \par .text C:\\Windows\\system32\\svchost.exe[1136] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00300F8B \par .text C:\\Windows\\system32\\svchost.exe[1136] msvcrt.dll!system 77C6804B 5 Bytes JMP 00300FA6 \par .text C:\\Windows\\system32\\svchost.exe[1136] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 00300FB7 \par .text C:\\Windows\\system32\\svchost.exe[1136] msvcrt.dll!_open 77C6D106 5 Bytes JMP 00300FEF \par .text C:\\Windows\\system32\\svchost.exe[1136] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 0030000C \par .text C:\\Windows\\system32\\svchost.exe[1136] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00300FD2 \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 002F0F9E \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 002F0FC0 \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 002F0000 \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 002F0FAF \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 002F0F83 \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 002F002C \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 002F001B \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 3 Bytes JMP 002F0FDB \par .text C:\\Windows\\system32\\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyExW + 4 77A37BA5 1 Byte [88]\par .text C:\\Windows\\system32\\svchost.exe[1136] WS2_32.dll!socket 769936D1 5 Bytes JMP 00290000 \par .text C:\\Windows\\system32\\svchost.exe[1144] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00750FEF \par .text C:\\Windows\\system32\\svchost.exe[1144] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00750011 \par .text C:\\Windows\\system32\\svchost.exe[1144] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00750000 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00740F63 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 007400B3 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00740F34 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 007400D5 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00740F92 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00740FEF \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00740040 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 007400A2 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00740FA3 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00740051 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 0074006C \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00740FD4 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00740091 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 007400E6 \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 0074001B \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 0074000A \par .text C:\\Windows\\system32\\svchost.exe[1144] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 007400C4 \par .text C:\\Windows\\system32\\svchost.exe[1144] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 007A0F88 \par .text C:\\Windows\\system32\\svchost.exe[1144] msvcrt.dll!system 77C6804B 5 Bytes JMP 007A0FA3 \par .text C:\\Windows\\system32\\svchost.exe[1144] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 007A0FC8 \par .text C:\\Windows\\system32\\svchost.exe[1144] msvcrt.dll!_open 77C6D106 5 Bytes JMP 007A0000 \par .text C:\\Windows\\system32\\svchost.exe[1144] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 007A001D \par .text C:\\Windows\\system32\\svchost.exe[1144] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 007A0FE3 \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00770F7C \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 00770FB2 \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00770FEF \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00770F97 \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 00770F6B \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 00770FCD \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00770FDE \par .text C:\\Windows\\system32\\svchost.exe[1144] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 0077001E \par .text C:\\Windows\\system32\\svchost.exe[1144] WS2_32.dll!socket 769936D1 5 Bytes JMP 00760FE5 \par .text C:\\Windows\\system32\\svchost.exe[1204] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00850FEF \par .text C:\\Windows\\system32\\svchost.exe[1204] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00850FD4 \par .text C:\\Windows\\system32\\svchost.exe[1204] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 0085000A \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00840F28 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00840F4D \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00840EF2 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 00840089 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00840067 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00840FD4 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00840FB9 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 00840F5E \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00840F8D \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00840025 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00840040 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00840F9E \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00840078 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 0084009A \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 0084000A \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 00840FE5 \par .text C:\\Windows\\system32\\svchost.exe[1204] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 00840F17 \par .text C:\\Windows\\system32\\svchost.exe[1204] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 008E0031 \par .text C:\\Windows\\system32\\svchost.exe[1204] msvcrt.dll!system 77C6804B 5 Bytes JMP 008E0FA6 \par .text C:\\Windows\\system32\\svchost.exe[1204] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 008E0FC1 \par .text C:\\Windows\\system32\\svchost.exe[1204] msvcrt.dll!_open 77C6D106 5 Bytes JMP 008E0FEF \par .text C:\\Windows\\system32\\svchost.exe[1204] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 008E0016 \par .text C:\\Windows\\system32\\svchost.exe[1204] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 008E0FD2 \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00870F83 \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 0087001B \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00870FEF \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00870F94 \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 0087004A \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 00870FCA \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00870000 \par .text C:\\Windows\\system32\\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 00870FAF \par .text C:\\Windows\\system32\\svchost.exe[1204] WS2_32.dll!socket 769936D1 5 Bytes JMP 00860FE5 \par .text C:\\Windows\\System32\\svchost.exe[1268] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00BB000A \par .text C:\\Windows\\System32\\svchost.exe[1268] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00BB0FD4 \par .text C:\\Windows\\System32\\svchost.exe[1268] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00BB0FE5 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00AD00B5 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00AD009A \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00AD00D7 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 00AD00C6 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00AD005D \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00AD0FD4 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00AD0FB9 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 00AD0089 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00AD004C \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00AD0F8D \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00AD002F \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00AD0FA8 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00AD0078 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 00AD00E8 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00AD0000 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 00AD0FE5 \par .text C:\\Windows\\System32\\svchost.exe[1268] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 00AD0F54 \par .text C:\\Windows\\System32\\svchost.exe[1268] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00F7005F \par .text C:\\Windows\\System32\\svchost.exe[1268] msvcrt.dll!system 77C6804B 5 Bytes JMP 00F70FDE \par .text C:\\Windows\\System32\\svchost.exe[1268] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 00F70033 \par .text C:\\Windows\\System32\\svchost.exe[1268] msvcrt.dll!_open 77C6D106 5 Bytes JMP 00F70000 \par .text C:\\Windows\\System32\\svchost.exe[1268] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 00F70044 \par .text C:\\Windows\\System32\\svchost.exe[1268] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00F70FEF \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00F60F94 \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 00F60FC0 \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00F60000 \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00F60FAF \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 00F60F83 \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 00F60FE5 \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00F60011 \par .text C:\\Windows\\System32\\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 00F60036 \par .text C:\\Windows\\System32\\svchost.exe[1268] WS2_32.dll!socket 769936D1 5 Bytes JMP 00BC0000 \par .text C:\\Windows\\system32\\svchost.exe[1308] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00650000 \par .text C:\\Windows\\system32\\svchost.exe[1308] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00650FE5 \par .text C:\\Windows\\system32\\svchost.exe[1308] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 0065001B \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 0062007B \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00620F2B \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00620EE4 \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 00620EFF \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00620F5E \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 0062000A \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 0062001B \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 00620F3C \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00620F6F \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 0062002C \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00620F80 \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00620FAF \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00620F4D \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 00620ED3 \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00620FD4 \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 00620FE5 \par .text C:\\Windows\\system32\\svchost.exe[1308] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 00620F10 \par .text C:\\Windows\\system32\\svchost.exe[1308] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00640FBC \par .text C:\\Windows\\system32\\svchost.exe[1308] msvcrt.dll!system 77C6804B 5 Bytes JMP 00640047 \par .text C:\\Windows\\system32\\svchost.exe[1308] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 00640022 \par .text C:\\Windows\\system32\\svchost.exe[1308] msvcrt.dll!_open 77C6D106 5 Bytes JMP 00640FEF \par .text C:\\Windows\\system32\\svchost.exe[1308] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 00640FCD \par .text C:\\Windows\\system32\\svchost.exe[1308] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00640FDE \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00630062 \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 00630040 \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00630FE5 \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00630051 \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 00630FAF \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 00630025 \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00630000 \par .text C:\\Windows\\system32\\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 00630FCA \par .text C:\\Windows\\system32\\svchost.exe[1308] WS2_32.dll!socket 769936D1 5 Bytes JMP 00610000 \par .text C:\\Windows\\system32\\svchost.exe[1316] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00E9000A \par .text C:\\Windows\\system32\\svchost.exe[1316] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00E90FDE \par .text C:\\Windows\\system32\\svchost.exe[1316] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00E90FEF \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 009D0F2B \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 009D0071 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 009D0096 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 009D0EFF \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 009D0056 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 009D0014 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 009D0FC3 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 009D0F50 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 009D0F7C \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 009D0039 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 009D0F97 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 009D0FB2 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 009D0F61 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 009D0EE4 \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 009D0FDE \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 009D0FEF \par .text C:\\Windows\\system32\\svchost.exe[1316] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 009D0F1A \par .text C:\\Windows\\system32\\svchost.exe[1316] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 009F0F7F \par .text C:\\Windows\\system32\\svchost.exe[1316] msvcrt.dll!system 77C6804B 5 Bytes JMP 009F0014 \par .text C:\\Windows\\system32\\svchost.exe[1316] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 009F0FB5 \par .text C:\\Windows\\system32\\svchost.exe[1316] msvcrt.dll!_open 77C6D106 5 Bytes JMP 009F0FEF \par .text C:\\Windows\\system32\\svchost.exe[1316] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 009F0F9A \par .text C:\\Windows\\system32\\svchost.exe[1316] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 009F0FC6 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 009E0073 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 009E0051 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 009E0000 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 009E0062 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 009E0FB6 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 009E0FE5 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 009E0011 \par .text C:\\Windows\\system32\\svchost.exe[1316] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 009E0036 \par .text C:\\Windows\\system32\\svchost.exe[1316] WS2_32.dll!socket 769936D1 5 Bytes JMP 009C0000 \par .text C:\\Windows\\System32\\svchost.exe[1344] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00F50FE5 \par .text C:\\Windows\\System32\\svchost.exe[1344] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00F5000A \par .text C:\\Windows\\System32\\svchost.exe[1344] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00F50FD4 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00F40097 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00F40F47 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00F40F1B \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 00F400B2 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00F40F7A \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00F40FEF \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00F40FD4 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 00F40F58 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00F40F8B \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00F40FB9 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00F40FA8 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00F40036 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00F40F69 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 00F40F0A \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00F4001B \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 00F40000 \par .text C:\\Windows\\System32\\svchost.exe[1344] kernel32.dll!WinExec 76A55CF7 5 Bytes JMP 00F40F36 \par .text C:\\Windows\\System32\\svchost.exe[1344] msvcrt.dll!_wsystem 77C67F2F 5 Bytes JMP 00FD004B \par .text C:\\Windows\\System32\\svchost.exe[1344] msvcrt.dll!system 77C6804B 5 Bytes JMP 00FD003A \par .text C:\\Windows\\System32\\svchost.exe[1344] msvcrt.dll!_creat 77C6BBE1 5 Bytes JMP 00FD0029 \par .text C:\\Windows\\System32\\svchost.exe[1344] msvcrt.dll!_open 77C6D106 5 Bytes JMP 00FD0000 \par .text C:\\Windows\\System32\\svchost.exe[1344] msvcrt.dll!_wcreat 77C6D326 5 Bytes JMP 00FD0FCA \par .text C:\\Windows\\System32\\svchost.exe[1344] msvcrt.dll!_wopen 77C6D501 5 Bytes JMP 00FD0FEF \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegCreateKeyExA 77A139AB 5 Bytes JMP 00F80F7C \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegCreateKeyA 77A13BA9 5 Bytes JMP 00F80FA8 \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegOpenKeyA 77A189C7 5 Bytes JMP 00F80FE5 \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegCreateKeyW 77A2391E 5 Bytes JMP 00F80F97 \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegCreateKeyExW 77A241F1 5 Bytes JMP 00F80F61 \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegOpenKeyExA 77A27C42 5 Bytes JMP 00F80FCA \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegOpenKeyW 77A2E2B5 5 Bytes JMP 00F80000 \par .text C:\\Windows\\System32\\svchost.exe[1344] ADVAPI32.dll!RegOpenKeyExW 77A37BA1 5 Bytes JMP 00F80FB9 \par .text C:\\Windows\\System32\\svchost.exe[1344] WS2_32.dll!socket 769936D1 5 Bytes JMP 00F60FEF \par .text C:\\Windows\\system32\\svchost.exe[1360] ntdll.dll!NtCreateFile 77D243D4 5 Bytes JMP 00E00000 \par .text C:\\Windows\\system32\\svchost.exe[1360] ntdll.dll!NtCreateProcess 77D24494 5 Bytes JMP 00E00FDE \par .text C:\\Windows\\system32\\svchost.exe[1360] ntdll.dll!NtProtectVirtualMemory 77D24D34 5 Bytes JMP 00E00FEF \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!GetStartupInfoW 769C1929 5 Bytes JMP 00DE00AE \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!GetStartupInfoA 769C19C9 5 Bytes JMP 00DE0F68 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreateProcessW 769C1BF3 5 Bytes JMP 00DE00EB \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreateProcessA 769C1C28 5 Bytes JMP 00DE00D0 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!VirtualProtect 769C1DC3 5 Bytes JMP 00DE0F94 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreateNamedPipeA 769C2EF5 5 Bytes JMP 00DE0FE5 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreateNamedPipeW 769C5C0C 5 Bytes JMP 00DE0040 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreatePipe 769E8E6E 5 Bytes JMP 00DE0093 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!LoadLibraryExW 769E9109 5 Bytes JMP 00DE0FA5 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!LoadLibraryW 769E9362 5 Bytes JMP 00DE0062 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!LoadLibraryExA 769E94B4 5 Bytes JMP 00DE0FB6 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!LoadLibraryA 769E94DC 5 Bytes JMP 00DE0051 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!VirtualProtectEx 769EDBDA 5 Bytes JMP 00DE0F83 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!GetProcAddress 76A0903B 5 Bytes JMP 00DE0106 \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreateFileW 76A0AECB 5 Bytes JMP 00DE001B \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!CreateFileA 76A0CE5F 5 Bytes JMP 00DE000A \par .text C:\\Windows\\system32\\svchost.exe[1360] kernel32.dll!WinExec |
| Themen zu PC läuft sehr langsam, svchost.exe lastet das System extrem aus |
| 32 bit, agere systems, autorun, bonjour, components, corp./icp, defender, desktop, device driver, ebay, error, explorer, firefox, firefox.exe, format, google, home, home premium, install.exe, kb973917, langsam, location, logfile, microsoft office 2003, mozilla, nvidia, nvlddmkm.sys, nvstor.sys, office 2007, oldtimer, otl logfile, otl.exe, pc läuft, picasa, plug-in, problem, programdata, realtek, registry, rundll, saver, search.hijacker, searchplugins, searchscopes, security, security update, sehr langsam, server, shell32.dll, skype.exe, software, staropen, start menu, studio, svchost.exe, system, torrent.exe, vista, visual studio, webdav |