76
Re: Malware problems and Internet Redirecting on Sat Aug 07, 2010 7:14 pm
033 F7B62000 00014000 VIDEOPRT.SYS YES YES
034 F7B3A000 00028000 HDAudBus.sys HDAudBus YES YES
035 F7B23000 00017000 jmcr.sys JMCR YES YES
036 F7B0B000 00018000 SCSIPORT.SYS YES YES
037 F79D0000 0013B000 bcmwl5.sys BCM43XX YES YES
038 F79B6000 0001A000 Rtenicxp.sys RTLE8023xp YES YES
039 F874C000 00006000 usbuhci.sys usbuhci YES YES
040 F7992000 00024000 USBPORT.SYS YES YES
041 F875C000 00008000 usbehci.sys usbehci YES YES
042 F8934000 00004000 CmBatt.sys CmBatt YES YES
043 F8514000 0000D000 i8042prt.sys i8042prt YES YES
044 F876C000 00006000 kbdclass.sys Kbdclass YES YES
045 F795A000 00038000 SynTP.sys SynTP YES YES
046 F897C000 00002000 USBD.SYS YES YES
047 F877C000 00006000 mouclass.sys Mouclass YES YES
048 F8B13000 00001000 audstub.sys audstub YES YES
049 F8524000 0000D000 rasl2tp.sys Rasl2tp YES YES
050 F893C000 00003000 ndistapi.sys NdisTapi YES YES
051 F7943000 00017000 ndiswan.sys NdisWan YES YES
052 F8534000 0000B000 raspppoe.sys RasPppoe YES YES
053 F8544000 0000C000 raspptp.sys PptpMiniport YES YES
054 F879C000 00005000 TDI.SYS YES YES
055 F790A000 00011000 psched.sys PSched YES YES
056 F8554000 00009000 msgpc.sys Gpc YES YES
057 F87AC000 00005000 ptilink.sys Ptilink YES YES
058 F87BC000 00005000 raspti.sys Raspti YES YES
059 F8564000 0000A000 termdd.sys TermDD YES YES
060 F8982000 00002000 swenum.sys swenum YES YES
061 F78E7000 00023000 ks.sys YES YES
062 F7889000 0005E000 update.sys Update YES YES
063 F8954000 00004000 mssmbios.sys mssmbios YES YES
064 F8574000 0000A000 NDProxy.SYS NDProxy YES YES
065 F8594000 0000F000 usbhub.sys usbhub YES YES
066 AA310000 004B0000 RtkHDAud.sys IntcAzAudAddService YES YES
067 AA2EC000 00024000 portcls.sys YES YES
068 F85A4000 0000F000 drmk.sys YES YES
069 F7937000 00003000 i2omgmt.SYS i2omgmt YES YES
070 F898C000 00002000 Fs_Rec.SYS Fs_Rec YES YES
071 F8B5B000 00001000 Null.SYS Null YES YES
072 F8990000 00002000 Beep.SYS Beep YES YES
073 F882C000 00007000 HIDPARSE.SYS YES YES
074 F8834000 00006000 vga.sys VgaSave YES YES
075 F8994000 00002000 mnmdd.SYS mnmdd YES YES
076 F8998000 00002000 RDPCDD.sys RDPCDD YES YES
077 F8844000 00005000 Msfs.SYS Msfs YES YES
078 F8854000 00008000 Npfs.SYS Npfs YES YES
079 F7927000 00003000 rasacd.sys RasAcd YES YES
080 AA269000 00013000 ipsec.sys IPSec YES YES
081 AA210000 00059000 tcpip.sys Tcpip YES YES
082 AA1C0000 00028000 netbt.sys NetBT YES YES
083 AA19A000 00026000 ipnat.sys IpNat YES YES
084 F85C4000 00009000 wanarp.sys Wanarp YES YES
085 AA178000 00022000 afd.sys AFD YES YES
086 F85D4000 00009000 netbios.sys NetBIOS YES YES
087 AA0AD000 0002B000 rdbss.sys Rdbss YES YES
088 AA03D000 00070000 mrxsmb.sys MRxSmb YES YES
089 F8604000 0000B000 Fips.SYS Fips YES YES
090 AA025000 00018000 dump_atapi.sys NO NO
091 F899E000 00002000 dump_WMILIB.SYS NO NO
092 BF800000 001C7000 win32k.sys YES YES
093 AA2B4000 00003000 Dxapi.sys YES YES
094 F870C000 00005000 watchdog.sys YES YES
095 BF000000 00012000 dxg.sys YES YES
096 F8A96000 00001000 dxgthk.sys YES YES
097 BF024000 0002B000 igxpgd32.dll YES YES
098 BF012000 00012000 igxprd32.dll YES YES
099 BF04F000 00198000 igxpdv32.DLL YES YES
100 BF1E7000 00293000 igxpdx32.DLL YES YES
101 BFFA0000 00046000 ATMFD.DLL YES YES
102 A9F0D000 00004000 ndisuio.sys Ndisuio YES YES
103 A9D50000 0002D000 mrxdav.sys MRxDAV YES YES
104 A9A29000 00057000 srv.sys Srv YES YES
105 A9A14000 00015000 wdmaud.sys wdmaud YES YES
106 A9C08000 0000F000 sysaudio.sys sysaudio YES YES
107 A936B000 00041000 HTTP.sys HTTP YES YES
108 A98CA000 00004000 sdthlpr.sys SDTHelper YES NO
109 A8FA9000 00024000 Fastfat.SYS Fastfat YES YES
110 7C900000 000B2000 ntdll.dll YES YES
Number of Module Table entries patched = 0
22:26:12 - Performing check: "SDT hooks":
Found KiServiceTable @ 8055C700
0 ZwAcceptConnectPort 805A45F6
1 ZwAccessCheck 805F0AD8
2 ZwAccessCheckAndAuditAlarm 805F430E
3 ZwAccessCheckByType 805F0B0A
4 ZwAccessCheckByTypeAndAuditAlarm 805F4348
5 ZwAccessCheckByTypeResultList 805F0B40
6 ZwAccessCheckByTypeResultListAndAuditAlarm 805F438C
7 ZwAccessCheckByTypeResultListAndAuditAlarmByHandle 805F43D0
8 ZwAddAtom 806153D4
9 ZwAddBootEntry 80616108
10 ZwAdjustGroupsToken 805EBEBE
11 ZwAdjustPrivilegesToken 805EBB16
12 ZwAlertResumeThread 805D4B1E
13 ZwAlertThread 805D4ACE
14 ZwAllocateLocallyUniqueId 806159FA
15 ZwAllocateUserPhysicalPages 805B5F62
16 ZwAllocateUuids 80615016
17 ZwAllocateVirtualMemory 805A8A80
18 ZwAreMappedFilesTheSame 805B0576
19 ZwAssignProcessToJobObject 805D65E2
20 ZwCallbackReturn 8050189C
21 ZwCancelDeviceWakeupRequest 805C861C
22 ZwCancelIoFile 80576AE6
23 ZwCancelTimer 80538BEE
24 ZwClearEvent 8060E5E4
25 ZwClose 805BC4DC
26 ZwCloseObjectAuditAlarm 805F4848
27 ZwCompactKeys 80623398
28 ZwCompareTokens 805F8D5C
29 ZwCompleteConnectPort 805A4CE4
30 ZwCompressKey 806235EC
31 ZwConnectPort 805A4596
32 ZwContinue 80544EA4
33 ZwCreateDebugObject 80642132
34 ZwCreateDirectoryObject 805BE48C
35 ZwCreateEvent 8060E634
36 ZwCreateEventPair 8061697E
37 ZwCreateFile 80579084
38 ZwCreateIoCompletion 80578A62
39 ZwCreateJobObject 805D55A6
40 ZwCreateJobSet 805D52DE
41 ZwCreateKey 806237C8
42 ZwCreateMailslotFile 80579192
43 ZwCreateMutant 80616D76
44 ZwCreateNamedPipeFile 805790BE
45 ZwCreatePagingFile 805AB9B4
46 ZwCreatePort 805A50B2
47 ZwCreateProcess 805D11EA
48 ZwCreateProcessEx 805D1134
49 ZwCreateProfile 80617196
50 ZwCreateSection 805AB38E
51 ZwCreateSemaphore 80614734
52 ZwCreateSymbolicLinkObject 805C39A6
53 ZwCreateThread 805D0FD2
54 ZwCreateTimer 80616646
55 ZwCreateToken 805F9104
56 ZwCreateWaitablePort 805A50D6
57 ZwDebugActiveProcess 8064320E
58 ZwDebugContinue 8064335E
59 ZwDelayExecution 80616058
60 ZwDeleteAtom 8061588A
61 ZwDeleteBootEntry 805C861C
62 ZwDeleteFile 80576C2C
63 ZwDeleteKey 80623C64
64 ZwDeleteObjectAuditAlarm 805F4954
65 ZwDeleteValueKey 80623E34
66 ZwDeviceIoControlFile 8057924A
67 ZwDisplayString 806126B2
68 ZwDuplicateObject 805BDFB4
69 ZwDuplicateToken 805ECD6C
70 ZwEnumerateBootEntries 80616108
71 ZwEnumerateKey 80624014
72 ZwEnumerateSystemEnvironmentValuesEx 806160FA
73 ZwEnumerateValueKey 8062427E
74 ZwExtendSection 805B3C82
75 ZwFilterToken 805ECF18
76 ZwFindAtom 8061563E
77 ZwFlushBuffersFile 80576CF8
78 ZwFlushInstructionCache 805B67F6
79 ZwFlushKey 806244E8
80 ZwFlushVirtualMemory 805AC6C8
81 ZwFlushWriteBuffer 805B6798
82 ZwFreeUserPhysicalPages 805B6304
83 ZwFreeVirtualMemory 805B2F5E
84 ZwFsControlFile 8057927E
85 ZwGetContextThread 805D14E4
86 ZwGetDevicePowerState 805C863E
87 ZwGetPlugPlayEvent 80599116
88 ZwGetWriteWatch 80521196
89 ZwImpersonateAnonymousToken 805F8A50
90 ZwImpersonateClientOfPort 805A5140
91 ZwImpersonateThread 805D77A2
92 ZwInitializeRegistry 8062190A
93 ZwInitiatePowerAction 805C8416
94 ZwIsProcessInJob 805D51A2
95 ZwIsSystemResumeAutomatic 805C862A
96 ZwListenPort 805A534C
97 ZwLoadDriver 8058413A
98 ZwLoadKey 806259EC
99 ZwLoadKey2 806255F8
100 ZwLockFile 805792B2
101 ZwLockProductActivationKeys 80612CA4
102 ZwLockRegistryKey 80623698
103 ZwLockVirtualMemory 805B68FE
104 ZwMakePermanentObject 805BE282
105 ZwMakeTemporaryObject 805BC580
106 ZwMapUserPhysicalPages 805B53C2
107 ZwMapUserPhysicalPagesScatter 805B5912
108 ZwMapViewOfSection 805B1FE6
109 ZwModifyBootEntry 805C861C
110 ZwNotifyChangeDirectoryFile 80579ECA
111 ZwNotifyChangeKey 806259B6
112 ZwNotifyChangeMultipleKeys 806245EA
113 ZwOpenDirectoryObject 805BE55E
114 ZwOpenEvent 8060E734
115 ZwOpenEventPair 80616A56
116 ZwOpenFile 8057A182
117 ZwOpenIoCompletion 80578B3A
118 ZwOpenJobObject 805D572C
119 ZwOpenKey 80624BA6
120 ZwOpenMutant 80616E4E
121 ZwOpenObjectAuditAlarm 805F4416
122 ZwOpenProcess 805CB3FA
123 ZwOpenProcessToken 805ED706
124 ZwOpenProcessTokenEx 805ED36A
125 ZwOpenSection 805AA3B2
126 ZwOpenSemaphore 8061482E
127 ZwOpenSymbolicLinkObject 805C3B8C
128 ZwOpenThread 805CB686
129 ZwOpenThreadToken 805ED724
130 ZwOpenThreadTokenEx 805ED4DA
131 ZwOpenTimer 80616768
132 ZwPlugPlayControl 80645400
133 ZwPowerInformation 805C94AC
134 ZwPrivilegeCheck 805F7B02
135 ZwPrivilegeObjectAuditAlarm 805F3728
136 ZwPrivilegedServiceAuditAlarm 805F3914
137 ZwProtectVirtualMemory 805B83CA
138 ZwPulseEvent 8060E7EC
139 ZwQueryAttributesFile 80576ED6
140 ZwQueryBootEntryOrder 80616108
141 ZwQueryBootOptions 80616108
142 ZwQueryDebugFilterState 8053FBD6
143 ZwQueryDefaultLocale 806103DE
144 ZwQueryDefaultUILanguage 8061103E
145 ZwQueryDirectoryFile 80579E64
146 ZwQueryDirectoryObject 805BE5FE
147 ZwQueryEaFile 8057A1B2
148 ZwQueryEvent 8060E8B4
149 ZwQueryFullAttributesFile 8057702A
150 ZwQueryInformationAtom 806158B2
151 ZwQueryInformationFile 8057AA1E
152 ZwQueryInformationJobObject 805D5BFE
153 ZwQueryInformationPort 805A53AA
154 ZwQueryInformationProcess 805CCF4E
155 ZwQueryInformationThread 805CBB7C
156 ZwQueryInformationToken 805ED804
157 ZwQueryInstallUILanguage 806107DC
158 ZwQueryIntervalProfile 80617618
159 ZwQueryIoCompletion 80578BE2
160 ZwQueryKey 80624EE8
161 ZwQueryMultipleValueKey 80622916
162 ZwQueryMutant 80616EF6
163 ZwQueryObject 805C5278
164 ZwQueryOpenSubKeys 80622FC2
165 ZwQueryPerformanceCounter 806176A6
166 ZwQueryQuotaInformationFile 8057B800
167 ZwQuerySection 805B858C
168 ZwQuerySecurityObject 805C0046
169 ZwQuerySemaphore 806148E6
170 ZwQuerySymbolicLinkObject 805C3C2C
171 ZwQuerySystemEnvironmentValue 80616124
172 ZwQuerySystemEnvironmentValueEx 806160EC
173 ZwQuerySystemInformation 806110BE
174 ZwQuerySystemTime 8061287E
175 ZwQueryTimer 80616820
176 ZwQueryTimerResolution 80612910
177 ZwQueryValueKey 806219EC
178 ZwQueryVirtualMemory 805B8C1A
179 ZwQueryVolumeInformationFile 8057BCEA
180 ZwQueueApcThread 805D1230
181 ZwRaiseException 80544EEC
182 ZwRaiseHardError 80614558
183 ZwReadFile 8057C48A
184 ZwReadFileScatter 8057C9F4
185 ZwReadRequestData 805A5E32
186 ZwReadVirtualMemory 805B426E
187 ZwRegisterThreadTerminatePort 805D2738
188 ZwReleaseMutant 8061702E
189 ZwReleaseSemaphore 80614A16
190 ZwRemoveIoCompletion 80578EDA
191 ZwRemoveProcessDebug 806432DE
192 ZwRenameKey 806231EA
193 ZwReplaceKey 8062589C
194 ZwReplyPort 805A54B2
195 ZwReplyWaitReceivePort 805A647A
196 ZwReplyWaitReceivePortEx 805A5E82
197 ZwReplyWaitReplyPort 805A579C
198 ZwRequestDeviceWakeup 805C85AE
199 ZwRequestPort 805A2A10
200 ZwRequestWaitReplyPort 805A2D3C
201 ZwRequestWakeupLatency 805C83BC
202 ZwResetEvent 8060E9C6
203 ZwResetWriteWatch 8052167E
204 ZwRestoreKey 806251A8
205 ZwResumeProcess 805D4A78
206 ZwResumeThread 805D495A
207 ZwSaveKey 806252A4
208 ZwSaveKeyEx 8062538A
209 ZwSaveMergedKeys 806254B2
210 ZwSecureConnectPort 805A3D2A
211 ZwSetBootEntryOrder 80616108
212 ZwSetBootOptions 80616108
213 ZwSetContextThread 805D16F4
214 ZwSetDebugFilterState 80645F96
215 ZwSetDefaultHardErrorPort 80614402
216 ZwSetDefaultLocale 8061052E
217 ZwSetDefaultUILanguage 80610DA0
218 ZwSetEaFile 8057A6C6
219 ZwSetEvent 8060EA86
220 ZwSetEventBoostPriority 8060EB50
221 ZwSetHighEventPair 80616D12
222 ZwSetHighWaitLowEventPair 80616C42
223 ZwSetInformationDebugObject 80642CA8
224 ZwSetInformationFile 8057B010
225 ZwSetInformationJobObject 805D690C
226 ZwSetInformationKey 806224E2
227 ZwSetInformationObject 805C47EE
228 ZwSetInformationProcess 805CDE44
229 ZwSetInformationThread 805CC0C8
230 ZwSetInformationToken 805F9E7E
231 ZwSetIntervalProfile 8061717A
232 ZwSetIoCompletion 80578E78
233 ZwSetLdtEntries 805D38A4
234 ZwSetLowEventPair 80616CAE
235 ZwSetLowWaitHighEventPair 80616BD6
236 ZwSetQuotaInformationFile 8057B7DE
237 ZwSetSecurityObject 805C05DA
238 ZwSetSystemEnvironmentValue 806163A8
239 ZwSetSystemEnvironmentValueEx 806160EC
240 ZwSetSystemInformation 8060F3EC
241 ZwSetSystemPowerState 80652E18
242 ZwSetSystemTime 80613B86
243 ZwSetThreadExecutionState 805C82D0
244 ZwSetTimer 80538D7E
245 ZwSetTimerResolution 80613058
246 ZwSetUuidSeed 80614ECC
247 ZwSetValueKey 80621D3A
248 ZwSetVolumeInformationFile 8057C0F4
249 ZwShutdownSystem 80612676
250 ZwSignalAndWaitForSingleObject 80526774
251 ZwStartProfile 806173C4
252 ZwStopProfile 8061756E
253 ZwSuspendProcess 805D4A22
254 ZwSuspendThread 805D4894
255 ZwSystemDebugControl 80617792
256 ZwTerminateJobObject 805D74A0
257 ZwTerminateProcess 805D2982
258 ZwTerminateThread 805D2B7C
259 ZwTestAlert 805D4BE2
260 ZwTraceEvent 80535114
261 ZwTranslateFilePath 80616116
262 ZwUnloadDriver 805842CE
263 ZwUnloadKey 80622064
264 ZwUnloadKeyEx 80622286
265 ZwUnlockFile 80579656
266 ZwUnlockVirtualMemory 805B6E8C
267 ZwUnmapViewOfSection 805B2DF4
268 ZwVdmControl 805FB236
269 ZwWaitForDebugEvent 80642A10
270 ZwWaitForMultipleObjects 805C0790
271 ZwWaitForSingleObject 805C06A6
272 ZwWaitHighEventPair 80616B72
273 ZwWaitLowEventPair 80616B0E
274 ZwWriteFile 8057CEF2
275 ZwWriteFileGather 8057D4D6
276 ZwWriteRequestData 805A5E5A
277 ZwWriteVirtualMemory 805B4378
278 ZwYieldExecution 80504AF4
279 ZwCreateKeyedEvent 80617BEA
280 ZwOpenKeyedEvent 80617CD4
281 ZwReleaseKeyedEvent 80617D86
282 ZwWaitForKeyedEvent 80617FE2
283 ZwQueryPortInformationProcess 805CB8FC
Number of Service Table entries hooked = 0
Number of Service Table entries patched = 0
22:26:13 - Performing check: "IDT hooks":
IDT offset in kernel: 0x0670AF54
IDT address: 0x8003F400 (phys.: 0x062EF400)
INT# SegType DPL ISR
000(00) IntG32 00 0008:805421C0
001(01) IntG32 00 0008:8054233C
002(02) TaskG32 00 0058:805528A6
003(03) IntG32 03 0008:80542750
004(04) IntG32 03 0008:805428D0
005(05) IntG32 00 0008:80542A30
006(06) IntG32 00 0008:80542BA4
007(07) IntG32 00 0008:8054321C
008(08) TaskG32 00 0050:80552898
009(09) IntG32 00 0008:80543620
010(0A) IntG32 00 0008:80543740
011(0B) IntG32 00 0008:80543880
012(0C) IntG32 00 0008:80543AE0
013(0D) IntG32 00 0008:80543DCC
014(0E) IntG32 00 0008:805444E0
015(0F) IntG32 00 0008:80544818
016(10) IntG32 00 0008:80544938
017(11) IntG32 00 0008:80544A74
018(12) TaskG32 00 00A0:02902B58 (hooked)
019(13) IntG32 00 0008:80544BDC
020(14) IntG32 00 0008:80544818
021(15) IntG32 00 0008:80544818
022(16) IntG32 00 0008:80544818
023(17) IntG32 00 0008:80544818
024(18) IntG32 00 0008:80544818
025(19) IntG32 00 0008:80544818
026(1A) IntG32 00 0008:80544818
027(1B) IntG32 00 0008:80544818
028(1C) IntG32 00 0008:80544818
029(1D) IntG32 00 0008:80544818
030(1E) IntG32 00 0008:80544818
031(1F) IntG32 00 0008:806E610C
032(20) Not present
033(21) Not present
034(22) Not present
035(23) Not present
036(24) Not present
037(25) Not present
038(26) Not present
039(27) Not present
040(28) Not present
041(29) Not present
042(2A) IntG32 03 0008:805419EE
043(2B) IntG32 03 0008:80541AF0
044(2C) IntG32 03 0008:80541CA0
045(2D) IntG32 03 0008:8054262C
046(2E) IntG32 03 0008:80541471
047(2F) IntG32 00 0008:80544818
048(30) IntG32 00 0008:80540B30
049(31) IntG32 00 0008:80540B3A
050(32) IntG32 00 0008:80540B44
051(33) IntG32 00 0008:80540B4E
052(34) IntG32 00 0008:80540B58
053(35) IntG32 00 0008:80540B62
054(36) IntG32 00 0008:80540B6C
055(37) IntG32 00 0008:806E5864
056(38) IntG32 00 0008:80540B80
057(39) IntG32 00 0008:80540B8A
058(3A) IntG32 00 0008:80540B94
059(3B) IntG32 00 0008:80540B9E
060(3C) IntG32 00 0008:80540BA8
061(3D) IntG32 00 0008:806E6E2C
062(3E) IntG32 00 0008:80540BBC
063(3F) IntG32 00 0008:80540BC6
064(40) IntG32 00 0008:80540BD0
065(41) IntG32 00 0008:806E6C88
066(42) IntG32 00 0008:80540BE4
067(43) IntG32 00 0008:80540BEE
068(44) IntG32 00 0008:80540BF8
069(45) IntG32 00 0008:80540C02
070(46) IntG32 00 0008:80540C0C
071(47) IntG32 00 0008:80540C16
072(48) IntG32 00 0008:80540C20
073(49) IntG32 00 0008:80540C2A
074(4A) IntG32 00 0008:80540C34
075(4B) IntG32 00 0008:80540C3E
076(4C) IntG32 00 0008:80540C48
077(4D) IntG32 00 0008:80540C52
078(4E) IntG32 00 0008:80540C5C
079(4F) IntG32 00 0008:80540C66
080(50) IntG32 00 0008:806E593C
081(51) IntG32 00 0008:80540C7A
082(52) IntG32 00 0008:80540C84
083(53) IntG32 00 0008:80540C8E
084(54) IntG32 00 0008:80540C98
085(55) IntG32 00 0008:80540CA2
086(56) IntG32 00 0008:80540CAC
087(57) IntG32 00 0008:80540CB6
088(58) IntG32 00 0008:80540CC0
089(59) IntG32 00 0008:80540CCA
090(5A) IntG32 00 0008:80540CD4
091(5B) IntG32 00 0008:80540CDE
092(5C) IntG32 00 0008:80540CE8
093(5D) IntG32 00 0008:80540CF2
094(5E) IntG32 00 0008:80540CFC
095(5F) IntG32 00 0008:80540D06
096(60) IntG32 00 0008:80540D10
097(61) IntG32 00 0008:80540D1A
098(62) IntG32 00 0008:823D0044 (hooked)
099(63) IntG32 00 0008:821B1044 (hooked)
100(64) IntG32 00 0008:80540D38
101(65) IntG32 00 0008:80540D42
102(66) IntG32 00 0008:80540D4C
103(67) IntG32 00 0008:80540D56
104(68) IntG32 00 0008:80540D60
105(69) IntG32 00 0008:80540D6A
106(6A) IntG32 00 0008:80540D74
107(6B) IntG32 00 0008:80540D7E
108(6C) IntG32 00 0008:80540D88
109(6D) IntG32 00 0008:80540D92
110(6E) IntG32 00 0008:80540D9C
111(6F) IntG32 00 0008:80540DA6
112(70) IntG32 00 0008:80540DB0
113(71) IntG32 00 0008:80540DBA
114(72) IntG32 00 0008:80540DC4
115(73) IntG32 00 0008:81EB4BEC (hooked)
116(74) IntG32 00 0008:80540DD8
117(75) IntG32 00 0008:80540DE2
118(76) IntG32 00 0008:80540DEC
119(77) IntG32 00 0008:80540DF6
120(78) IntG32 00 0008:80540E00
121(79) IntG32 00 0008:80540E0A
122(7A) IntG32 00 0008:80540E14
123(7B) IntG32 00 0008:80540E1E
124(7C) IntG32 00 0008:80540E28
125(7D) IntG32 00 0008:80540E32
126(7E) IntG32 00 0008:80540E3C
127(7F) IntG32 00 0008:80540E46
128(80) IntG32 00 0008:80540E50
129(81) IntG32 00 0008:80540E5A
130(82) IntG32 00 0008:80540E64
131(83) IntG32 00 0008:81AA256C (hooked)
132(84) IntG32 00 0008:80540E78
133(85) IntG32 00 0008:80540E82
134(86) IntG32 00 0008:80540E8C
135(87) IntG32 00 0008:80540E96
136(88) IntG32 00 0008:80540EA0
137(89) IntG32 00 0008:80540EAA
138(8A) IntG32 00 0008:80540EB4
139(8B) IntG32 00 0008:80540EBE
140(8C) IntG32 00 0008:80540EC8
141(8D) IntG32 00 0008:80540ED2
142(8E) IntG32 00 0008:80540EDC
143(8F) IntG32 00 0008:80540EE6
144(90) IntG32 00 0008:80540EF0
145(91) IntG32 00 0008:80540EFA
146(92) IntG32 00 0008:80540F04
147(93) IntG32 00 0008:821B0BEC (hooked)
148(94) IntG32 00 0008:8198D974 (hooked)
149(95) IntG32 00 0008:80540F22
150(96) IntG32 00 0008:80540F2C
151(97) IntG32 00 0008:80540F36
152(98) IntG32 00 0008:80540F40
153(99) IntG32 00 0008:80540F4A
154(9A) IntG32 00 0008:80540F54
155(9B) IntG32 00 0008:80540F5E
156(9C) IntG32 00 0008:80540F68
157(9D) IntG32 00 0008:80540F72
158(9E) IntG32 00 0008:80540F7C
159(9F) IntG32 00 0008:80540F86
160(A0) IntG32 00 0008:80540F90
161(A1) IntG32 00 0008:80540F9A
162(A2) IntG32 00 0008:80540FA4
163(A3) IntG32 00 0008:821B14D4 (hooked)
164(A4) IntG32 00 0008:8215E044 (hooked)
165(A5) IntG32 00 0008:80540FC2
166(A6) IntG32 00 0008:80540FCC
167(A7) IntG32 00 0008:80540FD6
168(A8) IntG32 00 0008:80540FE0
169(A9) IntG32 00 0008:80540FEA
170(AA) IntG32 00 0008:80540FF4
171(AB) IntG32 00 0008:80540FFE
172(AC) IntG32 00 0008:80541008
173(AD) IntG32 00 0008:80541012
174(AE) IntG32 00 0008:8054101C
175(AF) IntG32 00 0008:80541026
176(B0) IntG32 00 0008:80541030
177(B1) IntG32 00 0008:82374BEC (hooked)
178(B2) IntG32 00 0008:80541044
179(B3) IntG32 00 0008:8054104E
180(B4) IntG32 00 0008:821AB974 (hooked)
181(B5) IntG32 00 0008:80541062
182(B6) IntG32 00 0008:8054106C
183(B7) IntG32 00 0008:80541076
184(B8) IntG32 00 0008:80541080
185(B9) IntG32 00 0008:8054108A
186(BA) IntG32 00 0008:80541094
187(BB) IntG32 00 0008:8054109E
188(BC) IntG32 00 0008:805410A8
189(BD) IntG32 00 0008:805410B2
190(BE) IntG32 00 0008:805410BC
191(BF) IntG32 00 0008:805410C6
192(C0) IntG32 00 0008:805410D0
193(C1) IntG32 00 0008:806E5AC0
194(C2) IntG32 00 0008:805410E4
195(C3) IntG32 00 0008:805410EE
196(C4) IntG32 00 0008:805410F8
197(C5) IntG32 00 0008:80541102
198(C6) IntG32 00 0008:8054110C
199(C7) IntG32 00 0008:80541116
200(C8) IntG32 00 0008:80541120
201(C9) IntG32 00 0008:8054112A
202(CA) IntG32 00 0008:80541134
203(CB) IntG32 00 0008:8054113E
204(CC) IntG32 00 0008:80541148
205(CD) IntG32 00 0008:80541152
206(CE) IntG32 00 0008:8054115C
207(CF) IntG32 00 0008:80541166
208(D0) IntG32 00 0008:80541170
209(D1) IntG32 00 0008:806E4E54
210(D2) IntG32 00 0008:80541184
211(D3) IntG32 00 0008:8054118E
212(D4) IntG32 00 0008:80541198
213(D5) IntG32 00 0008:805411A2
214(D6) IntG32 00 0008:805411AC
215(D7) IntG32 00 0008:805411B6
216(D8) IntG32 00 0008:805411C0
217(D9) IntG32 00 0008:805411CA
218(DA) IntG32 00 0008:805411D4
219(DB) IntG32 00 0008:805411DE
220(DC) IntG32 00 0008:805411E8
221(DD) IntG32 00 0008:805411F2
222(DE) IntG32 00 0008:805411FC
223(DF) IntG32 00 0008:80541206
224(E0) IntG32 00 0008:80541210
225(E1) IntG32 00 0008:806E6048
226(E2) IntG32 00 0008:80541224
227(E3) IntG32 00 0008:806E5DAC
228(E4) IntG32 00 0008:80541238
229(E5) IntG32 00 0008:80541242
230(E6) IntG32 00 0008:8054124C
231(E7) IntG32 00 0008:80541256
232(E8) IntG32 00 0008:80541260
233(E9) IntG32 00 0008:8054126A
234(EA) IntG32 00 0008:80541274
235(EB) IntG32 00 0008:8054127E
236(EC) IntG32 00 0008:80541288
237(ED) IntG32 00 0008:80541292
238(EE) IntG32 00 0008:80541299
239(EF) IntG32 00 0008:805412A0
240(F0) IntG32 00 0008:805412A7
241(F1) IntG32 00 0008:805412AE
242(F2) IntG32 00 0008:805412B5
243(F3) IntG32 00 0008:805412BC
244(F4) IntG32 00 0008:805412C3
245(F5) IntG32 00 0008:805412CA
246(F6) IntG32 00 0008:805412D1
247(F7) IntG32 00 0008:805412D8
248(F8) IntG32 00 0008:805412DF
249(F9) IntG32 00 0008:805412E6
250(FA) IntG32 00 0008:805412ED
251(FB) IntG32 00 0008:805412F4
252(FC) IntG32 00 0008:805412FB
253(FD) IntG32 00 0008:806E65A8
254(FE) IntG32 00 0008:806E6748
255(FF) IntG32 00 0008:80541310
22:26:14 - Performing check: "SYSENTER hook":
SYSENTER offset in kernel: 0x0046A540 (=0x80541540)
SYSENTER EIP: 0008:80541540 [OK]
22:26:14 - Performing check: "IAT hooks":
PID 768 - C:\WINDOWS\System32\smss.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
PID 816 - C:\WINDOWS\system32\csrss.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
CSRSRV.dll (75B40000 - 75B4B000)
basesrv.dll (75B50000 - 75B60000)
winsrv.dll (75B60000 - 75BAB000)
GDI32.dll (77F10000 - 77F59000)
KERNEL32.dll (7C800000 - 7C8F6000)
USER32.dll (7E410000 - 7E4A1000)
sxs.dll (7E720000 - 7E7D0000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
Apphelp.dll (77B40000 - 77B62000)
VERSION.dll (77C00000 - 77C08000)
PID 840 - C:\WINDOWS\system32\winlogon.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
AUTHZ.dll (776C0000 - 776D2000)
msvcrt.dll (77C10000 - 77C68000)
CRYPT32.dll (77A80000 - 77B15000)
MSASN1.dll (77B20000 - 77B32000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
NDdeApi.dll (75940000 - 75948000)
PROFMAP.dll (75930000 - 7593A000)
NETAPI32.dll (5B860000 - 5B8B5000)
USERENV.dll (769C0000 - 76A74000)
PSAPI.DLL (76BF0000 - 76BFB000)
REGAPI.dll (76BC0000 - 76BCF000)
SETUPAPI.dll (77920000 - 77A13000)
VERSION.dll (77C00000 - 77C08000)
WINSTA.dll (76360000 - 76370000)
WINTRUST.dll (76C30000 - 76C5E000)
IMAGEHLP.dll (76C90000 - 76CB8000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
IMM32.DLL (76390000 - 763AD000)
MSGINA.dll (75970000 - 75A68000)
COMCTL32.dll (5D090000 - 5D12A000)
ODBC32.dll (74320000 - 7435D000)
comdlg32.dll (763B0000 - 763F9000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)
comctl32.dll (773D0000 - 774D3000)
odbcint.dll (00970000 - 00987000)
SHSVCS.dll (776E0000 - 77703000)
sfc.dll (76BB0000 - 76BB5000)
sfc_os.dll (76C60000 - 76C8A000)
ole32.dll (774E0000 - 7761D000)
Apphelp.dll (77B40000 - 77B62000)
msctfime.ime (755C0000 - 755EE000)
sxs.dll (7E720000 - 7E7D0000)
WINSCARD.DLL (723D0000 - 723EC000)
WTSAPI32.dll (76F50000 - 76F58000)
uxtheme.dll (5AD70000 - 5ADA8000)
WINMM.dll (76B40000 - 76B6D000)
cscdll.dll (76600000 - 7661D000)
dimsntfy.dll (47020000 - 47028000)
WlNotify.dll (75950000 - 7596A000)
MPR.dll (71B20000 - 71B32000)
WINSPOOL.DRV (73000000 - 73026000)
rsaenh.dll (68000000 - 68036000)
SAMLIB.dll (71BF0000 - 71C03000)
msv1_0.dll (77C70000 - 77C95000)
cryptdll.dll (76790000 - 7679C000)
iphlpapi.dll (76D60000 - 76D79000)
cscui.dll (77A20000 - 77A74000)
wdmaud.drv (72D20000 - 72D29000)
xpsp2res.dll (01750000 - 01A15000)
NTMARTA.DLL (77690000 - 776B1000)
WLDAP32.dll (76F60000 - 76F8C000)
COMRes.dll (77050000 - 77115000)
OLEAUT32.dll (77120000 - 771AB000)
CLBCATQ.DLL (76FD0000 - 7704F000)
msacm32.drv (72D10000 - 72D18000)
MSACM32.dll (77BE0000 - 77BF5000)
midimap.dll (77BD0000 - 77BD7000)
igfxdev.dll (10000000 - 10036000)
PID 884 - C:\WINDOWS\system32\services.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
msvcrt.dll (77C10000 - 77C68000)
NCObjAPI.DLL (5F770000 - 5F77C000)
MSVCP60.dll (76080000 - 760E5000)
SCESRV.dll (7DBD0000 - 7DC21000)
AUTHZ.dll (776C0000 - 776D2000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
USERENV.dll (769C0000 - 76A74000)
umpnpmgr.dll (7DBA0000 - 7DBC1000)
WINSTA.dll (76360000 - 76370000)
NETAPI32.dll (5B860000 - 5B8B5000)
ShimEng.dll (5CB70000 - 5CB96000)
AcAdProc.dll (47260000 - 4726F000)
IMM32.DLL (76390000 - 763AD000)
Apphelp.dll (77B40000 - 77B62000)
VERSION.dll (77C00000 - 77C08000)
eventlog.dll (77B70000 - 77B81000)
PSAPI.DLL (76BF0000 - 76BFB000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
wtsapi32.dll (76F50000 - 76F58000)
PID 896 - C:\WINDOWS\system32\lsass.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
LSASRV.dll (75730000 - 757E5000)
MPR.dll (71B20000 - 71B32000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
MSASN1.dll (77B20000 - 77B32000)
msvcrt.dll (77C10000 - 77C68000)
NETAPI32.dll (5B860000 - 5B8B5000)
NTDSAPI.dll (767A0000 - 767B3000)
DNSAPI.dll (76F20000 - 76F47000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
WLDAP32.dll (76F60000 - 76F8C000)
SAMLIB.dll (71BF0000 - 71C03000)
SAMSRV.dll (74440000 - 744AA000)
cryptdll.dll (76790000 - 7679C000)
ShimEng.dll (5CB70000 - 5CB96000)
AcGenral.DLL (6F880000 - 6FA4A000)
WINMM.dll (76B40000 - 76B6D000)
ole32.dll (774E0000 - 7761D000)
OLEAUT32.dll (77120000 - 771AB000)
MSACM32.dll (77BE0000 - 77BF5000)
VERSION.dll (77C00000 - 77C08000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)
USERENV.dll (769C0000 - 76A74000)
UxTheme.dll (5AD70000 - 5ADA8000)
IMM32.DLL (76390000 - 763AD000)
comctl32.dll (773D0000 - 774D3000)
comctl32.dll (5D090000 - 5D12A000)
msprivs.dll (4D200000 - 4D20E000)
kerberos.dll (71CF0000 - 71D3C000)
msv1_0.dll (77C70000 - 77C95000)
iphlpapi.dll (76D60000 - 76D79000)
netlogon.dll (744B0000 - 74515000)
w32time.dll (767C0000 - 767EC000)
MSVCP60.dll (76080000 - 760E5000)
schannel.dll (767F0000 - 76818000)
CRYPT32.dll (77A80000 - 77B15000)
wdigest.dll (7DFC0000 - 7DFD1000)
rsaenh.dll (68000000 - 68036000)
setupapi.dll (77920000 - 77A13000)
scecli.dll (74410000 - 7443F000)
ipsecsvc.dll (743E0000 - 7440F000)
AUTHZ.dll (776C0000 - 776D2000)
oakley.DLL (75D90000 - 75E60000)
WINIPSEC.DLL (74370000 - 7437B000)
pstorsvc.dll (743A0000 - 743AB000)
psbase.dll (743C0000 - 743DB000)
mswsock.dll (71A50000 - 71A8F000)
hnetcfg.dll (662B0000 - 66308000)
wshtcpip.dll (71A90000 - 71A98000)
dssenh.dll (68100000 - 68126000)
PID 1064 - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
ShimEng.dll (5CB70000 - 5CB96000)
AcGenral.DLL (6F880000 - 6FA4A000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
WINMM.dll (76B40000 - 76B6D000)
ole32.dll (774E0000 - 7761D000)
msvcrt.dll (77C10000 - 77C68000)
OLEAUT32.dll (77120000 - 771AB000)
MSACM32.dll (77BE0000 - 77BF5000)
VERSION.dll (77C00000 - 77C08000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)
USERENV.dll (769C0000 - 76A74000)
UxTheme.dll (5AD70000 - 5ADA8000)
IMM32.DLL (76390000 - 763AD000)
comctl32.dll (773D0000 - 774D3000)
comctl32.dll (5D090000 - 5D12A000)
NTMARTA.DLL (77690000 - 776B1000)
SAMLIB.dll (71BF0000 - 71C03000)
WLDAP32.dll (76F60000 - 76F8C000)
rpcss.dll (76A80000 - 76AE4000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
xpsp2res.dll (006B0000 - 00975000)
CLBCATQ.DLL (76FD0000 - 7704F000)
COMRes.dll (77050000 - 77115000)
Apphelp.dll (77B40000 - 77B62000)
termsrv.dll (760F0000 - 76143000)
ICAAPI.dll (74F70000 - 74F76000)
SETUPAPI.dll (77920000 - 77A13000)
WINTRUST.dll (76C30000 - 76C5E000)
CRYPT32.dll (77A80000 - 77B15000)
MSASN1.dll (77B20000 - 77B32000)
IMAGEHLP.dll (76C90000 - 76CB8000)
AUTHZ.dll (776C0000 - 776D2000)
mstlsapi.dll (75110000 - 7512F000)
ACTIVEDS.dll (77CC0000 - 77CF2000)
adsldpc.dll (76E10000 - 76E35000)
NETAPI32.dll (5B860000 - 5B8B5000)
ATL.DLL (76B20000 - 76B31000)
REGAPI.dll (76BC0000 - 76BCF000)
rsaenh.dll (68000000 - 68036000)
msi.dll (7D1E0000 - 7D49C000)
PID 1132 - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
ShimEng.dll (5CB70000 - 5CB96000)
AcGenral.DLL (6F880000 - 6FA4A000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
WINMM.dll (76B40000 - 76B6D000)
ole32.dll (774E0000 - 7761D000)
msvcrt.dll (77C10000 - 77C68000)
OLEAUT32.dll (77120000 - 771AB000)
MSACM32.dll (77BE0000 - 77BF5000)
VERSION.dll (77C00000 - 77C08000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)
USERENV.dll (769C0000 - 76A74000)
UxTheme.dll (5AD70000 - 5ADA8000)
IMM32.DLL (76390000 - 763AD000)
comctl32.dll (773D0000 - 774D3000)
comctl32.dll (5D090000 - 5D12A000)
rpcss.dll (76A80000 - 76AE4000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
xpsp2res.dll (006B0000 - 00975000)
rsaenh.dll (68000000 - 68036000)
mswsock.dll (71A50000 - 71A8F000)
hnetcfg.dll (662B0000 - 66308000)
wshtcpip.dll (71A90000 - 71A98000)
DNSAPI.dll (76F20000 - 76F47000)
iphlpapi.dll (76D60000 - 76D79000)
winrnr.dll (76FB0000 - 76FB8000)
WLDAP32.dll (76F60000 - 76F8C000)
rasadhlp.dll (76FC0000 - 76FC6000)
CLBCATQ.DLL (76FD0000 - 7704F000)
COMRes.dll (77050000 - 77115000)
msi.dll (7D1E0000 - 7D49C000)
PID 1172 - C:\WINDOWS\System32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
ShimEng.dll (5CB70000 - 5CB96000)
AcGenral.DLL (6F880000 - 6FA4A000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
WINMM.dll (76B40000 - 76B6D000)
ole32.dll (774E0000 - 7761D000)
msvcrt.dll (77C10000 - 77C68000)
OLEAUT32.dll (77120000 - 771AB000)
MSACM32.dll (77BE0000 - 77BF5000)
VERSION.dll (77C00000 - 77C08000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)
USERENV.dll (769C0000 - 76A74000)
UxTheme.dll (5AD70000 - 5ADA8000)
IMM32.DLL (76390000 - 763AD000)
comctl32.dll (773D0000 - 774D3000)
comctl32.dll (5D090000 - 5D12A000)
NTMARTA.DLL (77690000 - 776B1000)
SAMLIB.dll (71BF0000 - 71C03000)
WLDAP32.dll (76F60000 - 76F8C000)
xpsp2res.dll (00630000 - 008F5000)
shsvcs.dll (776E0000 - 77703000)
WINSTA.dll (76360000 - 76370000)
NETAPI32.dll (5B860000 - 5B8B5000)
dhcpcsvc.dll (7D4B0000 - 7D4D2000)
DNSAPI.dll (76F20000 - 76F47000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
iphlpapi.dll (76D60000 - 76D79000)
wzcsvc.dll (7DB10000 - 7DB9C000)
rtutils.dll (76E80000 - 76E8E000)
WMI.dll (76D30000 - 76D34000)
CRYPT32.dll (77A80000 - 77B15000)
MSASN1.dll (77B20000 - 77B32000)
EapolQec.dll (72810000 - 7281B000)
ATL.DLL (76B20000 - 76B31000)
QUtil.dll (726C0000 - 726D6000)
MSVCP60.dll (76080000 - 760E5000)
dot3api.dll (478C0000 - 478CA000)
WTSAPI32.dll (76F50000 - 76F58000)
ESENT.dll (606B0000 - 607BD000)
CLBCATQ.DLL (76FD0000 - 7704F000)
COMRes.dll (77050000 - 77115000)
rsaenh.dll (68000000 - 68036000)
rastls.dll (76B70000 - 76B97000)
CRYPTUI.dll (754D0000 - 75550000)
WININET.dll (3D930000 - 3DA16000)
Normaliz.dll (00B40000 - 00B49000)
urlmon.dll (78130000 - 78263000)
iertutil.dll (3DFD0000 - 3E1B8000)
WINTRUST.dll (76C30000 - 76C5E000)
IMAGEHLP.dll (76C90000 - 76CB8000)
MPRAPI.dll (76D40000 - 76D58000)
ACTIVEDS.dll (77CC0000 - 77CF2000)
adsldpc.dll (76E10000 - 76E35000)
SETUPAPI.dll (77920000 - 77A13000)
RASAPI32.dll (76EE0000 - 76F1C000)
rasman.dll (76E90000 - 76EA2000)
TAPI32.dll (76EB0000 - 76EDF000)
SCHANNEL.dll (767F0000 - 76818000)
WinSCard.dll (723D0000 - 723EC000)
PSAPI.DLL (76BF0000 - 76BFB000)
raschap.dll (76BD0000 - 76BE6000)
schedsvc.dll (77300000 - 77333000)
NTDSAPI.dll (767A0000 - 767B3000)
msv1_0.dll (77C70000 - 77C95000)
cryptdll.dll (76790000 - 7679C000)
MSIDLE.DLL (74F50000 - 74F55000)
audiosrv.dll (708B0000 - 708BD000)
wkssvc.dll (76E40000 - 76E63000)
qmgr.dll (5B9F0000 - 5BA5B000)
MPR.dll (71B20000 - 71B32000)
SHFOLDER.dll (76780000 - 76789000)
WINHTTP.dll (4D4F0000 - 4D549000)
cryptsvc.dll (76CE0000 - 76CF2000)
certcli.dll (77B90000 - 77BC2000)
ersvc.dll (74F80000 - 74F89000)
es.dll (77710000 - 77754000)
pchsvc.dll (74F40000 - 74F4C000)
hidserv.dll (688E0000 - 688E9000)
HID.DLL (688F0000 - 688F9000)
mswsock.dll (71A50000 - 71A8F000)
hnetcfg.dll (662B0000 - 66308000)
wshtcpip.dll (71A90000 - 71A98000)
srvsvc.dll (75090000 - 750AA000)
netman.dll (77D00000 - 77D33000)
netshell.dll (76400000 - 765A5000)
credui.dll (76C00000 - 76C2E000)
dot3dlg.dll (736D0000 - 736D6000)
OneX.DLL (5DCA0000 - 5DCC8000)
eappcfg.dll (745B0000 - 745D2000)
eappprxy.dll (5DCD0000 - 5DCDE000)
WZCSAPI.DLL (73030000 - 73040000)
seclogon.dll (73D20000 - 73D28000)
sens.dll (722D0000 - 722DD000)
tapisrv.dll (733E0000 - 73420000)
w32time.dll (767C0000 - 767EC000)
wuauserv.dll (50000000 - 50005000)
wuaueng.dll (50040000 - 50219000)
WINSPOOL.DRV (73000000 - 73026000)
Cabinet.dll (75150000 - 75163000)
mspatcha.dll (600A0000 - 600AB000)
wmisvc.dll (59490000 - 594B8000)
VSSAPI.DLL (753E0000 - 7544D000)
trkwks.dll (75070000 - 75089000)
srsvc.dll (751A0000 - 751CE000)
POWRPROF.dll (74AD0000 - 74AD8000)
browser.dll (76DA0000 - 76DB6000)
wscsvc.dll (4C0A0000 - 4C0B7000)
msi.dll (7D1E0000 - 7D49C000)
SXS.DLL (7E720000 - 7E7D0000)
ipnathlp.dll (66460000 - 664B5000)
AUTHZ.dll (776C0000 - 776D2000)
wbemcomn.dll (75290000 - 752C7000)
sfc.dll (76BB0000 - 76BB5000)
sfc_os.dll (76C60000 - 76C8A000)
wbemcore.dll (762C0000 - 76345000)
esscli.dll (75310000 - 7534F000)
FastProx.dll (75690000 - 75706000)
comsvcs.dll (76620000 - 7675C000)
colbact.DLL (75130000 - 75144000)
MTXCLU.DLL (750F0000 - 75103000)
WSOCK32.dll (71AD0000 - 71AD9000)
CLUSAPI.DLL (76D10000 - 76D22000)
RESUTILS.DLL (750B0000 - 750C2000)
wmiutils.dll (75020000 - 7503B000)
repdrvfs.dll (75200000 - 7522F000)
Apphelp.dll (77B40000 - 77B62000)
wmiprvsd.dll (3F1E0000 - 3F252000)
NCObjAPI.DLL (5F770000 - 5F77C000)
wbemess.dll (75390000 - 753D6000)
ncprov.dll (5F740000 - 5F74E000)
upnp.dll (76DE0000 - 76E04000)
SSDPAPI.dll (74F00000 - 74F0C000)
msxml3.dll (74980000 - 74AA3000)
winrnr.dll (76FB0000 - 76FB8000)
rasadhlp.dll (76FC0000 - 76FC6000)
dssenh.dll (68100000 - 68126000)
advpack.dll (65000000 - 6502E000)
rasmans.dll (7DF30000 - 7DF62000)
WINIPSEC.DLL (74370000 - 7437B000)
netcfgx.dll (755F0000 - 7568A000)
rastapi.dll (75880000 - 75891000)
unimdm.tsp (57CC0000 - 57CF6000)
uniplat.dll (72000000 - 72007000)
RASDLG.dll (768D0000 - 76974000)
kmddsp.tsp (57D40000 - 57D4B000)
ndptsp.tsp (57D20000 - 57D30000)
ipconf.tsp (57D50000 - 57D58000)
h323.tsp (57D70000 - 57DB6000)
hidphone.tsp (57D60000 - 57D6A000)
rasppp.dll (72240000 - 72277000)
ntlsapi.dll (724B0000 - 724B6000)
kerberos.dll (71CF0000 - 71D3C000)
RASQEC.DLL (72AE0000 - 72AF3000)
wups2.dll (50F00000 - 50F0D000)
mlang.dll (75CF0000 - 75D81000)
xmlprovi.dll (4CB90000 - 4CBA0000)
PID 1288 - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
ShimEng.dll (5CB70000 - 5CB96000)
AcGenral.DLL (6F880000 - 6FA4A000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
WINMM.dll (76B40000 - 76B6D000)
ole32.dll (774E0000 - 7761D000)
msvcrt.dll (77C10000 - 77C68000)
OLEAUT32.dll (77120000 - 771AB000)
MSACM32.dll (77BE0000 - 77BF5000)
VERSION.dll (77C00000 - 77C08000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)
USERENV.dll (769C0000 - 76A74000)
UxTheme.dll (5AD70000 - 5ADA8000)
IMM32.DLL (76390000 - 763AD000)
comctl32.dll (773D0000 - 774D3000)
comctl32.dll (5D090000 - 5D12A000)
dnsrslvr.dll (76770000 - 7677D000)
DNSAPI.dll (76F20000 - 76F47000)
WS2_32.dll (71AB0000 - 71AC7000)
WS2HELP.dll (71AA0000 - 71AA8000)
iphlpapi.dll (76D60000 - 76D79000)
rsaenh.dll (68000000 - 68036000)
mswsock.dll (71A50000 - 71A8F000)
hnetcfg.dll (662B0000 - 66308000)
wshtcpip.dll (71A90000 - 71A98000)
PID 1320 - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll (7C900000 - 7C9B2000)
kernel32.dll (7C800000 - 7C8F6000)
ADVAPI32.dll (77DD0000 - 77E6B000)
RPCRT4.dll (77E70000 - 77F02000)
Secur32.dll (77FE0000 - 77FF1000)
ShimEng.dll (5CB70000 - 5CB96000)
AcGenral.DLL (6F880000 - 6FA4A000)
USER32.dll (7E410000 - 7E4A1000)
GDI32.dll (77F10000 - 77F59000)
WINMM.dll (76B40000 - 76B6D000)
ole32.dll (774E0000 - 7761D000)
msvcrt.dll (77C10000 - 77C68000)
OLEAUT32.dll (77120000 - 771AB000)
MSACM32.dll (77BE0000 - 77BF5000)
VERSION.dll (77C00000 - 77C08000)
SHELL32.dll (7C9C0000 - 7D1D7000)
SHLWAPI.dll (77F60000 - 77FD6000)













