Please could you direct me with any help, I should be okay following instructions I've done these a few times before
I'm not sure what I'm infected with but I feel something is there, any help would be a great help!
Thanks
FRISC0
EDIT:
Here is my DDS Log:
Quote
DDS (Ver_11-03-05.01) - NTFSx86
Run by Jamie at 15:50:34.28 on 01/04/2011
Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_22
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2047.579 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Jamie\Desktop\gmer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Users\Jamie\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = local;*.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [UPnPRemoteEndpointInfo] regsvr32 /s /u "c:\users\jamie\appdata\local\upnpremoteendpointinfo\UPnPRemoteEndpointInfo.dll"
uRun: [zpka6oPoqDdX] control.exe "c:\users\jamie\appdata\local\io2trlckr3\zpka6oPoqDdX.cpl",0,1
uRun: [Hgugi] rundll32.exe "c:\users\jamie\appdata\local\esokonej.dll",Startup
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jamie\appdata\roaming\mozilla\firefox\profiles\wkfz9qgz.default\
FF - prefs.js: browser.startup.homepage - hxxp://Google.co.uk
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\users\jamie\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\jamie\appdata\roaming\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\jamie\appdata\roaming\facebook\npfbplugin_1_0_3.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-31 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-3-31 301528]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-3-31 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-3-31 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-3-31 42184]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-23 21504]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-8-24 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-10-16 369256]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2008-6-27 335872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Camdrv30;Philips ToUcam XS;c:\windows\system32\drivers\camdrv30.sys [2001-8-17 171264]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-3-11 13224]
S3 RTLWUSB;802.11g USB2.0 WLAN Dongle;c:\windows\system32\drivers\RTL8187.sys [2008-6-27 335872]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [2009-3-11 90408]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [2009-3-11 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [2009-3-11 122024]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [2009-3-11 115368]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [2009-3-11 25768]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [2009-3-11 111784]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [2009-3-11 117544]
S3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM108.sys [2007-6-28 1310720]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-04-01 14:49:12 625664 ----a-w- c:\users\jamie\dds.scr
2011-03-31 18:31:01 -------- d-----w- c:\users\jamie\appdata\local\{418BCFCB-4472-48FB-A67C-F0A800FB5462}
2011-03-30 23:15:42 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-30 23:15:41 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-30 23:14:44 40648 ----a-w- c:\windows\avastSS.scr
2011-03-30 23:13:58 -------- d-----w- c:\program files\AVAST Software
2011-03-30 23:13:58 -------- d-----w- c:\progra~2\AVAST Software
2011-03-30 22:21:55 0 ----a-w- c:\users\jamie\appdata\local\Syowobe.bin
2011-03-30 22:21:52 -------- d-----w- c:\users\jamie\appdata\local\{5384F7E6-9104-4F09-B1F0-72A183ECAC0A}
2011-03-30 13:50:43 -------- d-----w- c:\users\jamie\appdata\local\{97808D4A-D5FA-43D3-95AE-A42CD7F07FA5}
2011-03-29 17:38:51 -------- d-----w- c:\users\jamie\appdata\local\{941FEAB4-FE37-4D6F-A2BC-0779E3F0E90F}
2011-03-28 16:47:50 -------- d-----w- c:\users\jamie\appdata\local\{1F0EAAFC-2B5D-4E5F-BE98-C9A5553370E1}
2011-03-27 20:30:00 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-03-27 20:29:59 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-03-27 20:29:59 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-03-27 20:29:59 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-03-27 20:29:59 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-03-27 20:29:59 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-03-27 20:29:59 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-03-27 20:29:59 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-03-27 20:28:40 376480 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-03-26 18:38:55 -------- d-----w- c:\users\jamie\appdata\local\{FDC4747C-C5DA-403A-AB87-821480F8CA5C}
2011-03-23 11:09:09 -------- d-----w- c:\users\jamie\appdata\local\{5F57A843-32D5-4857-9AFC-E5C3D0857C2C}
2011-03-23 10:15:06 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-03-23 10:15:05 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-03-23 10:15:05 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-22 10:27:03 -------- d-----w- c:\users\jamie\appdata\local\{6233DC08-021B-4F62-B82E-14BA0E0AD1AC}
2011-03-22 10:26:42 -------- d-----w- c:\users\jamie\appdata\local\{A7AD0566-CD0C-4C61-8161-0FE786F7206A}
2011-03-20 21:46:39 -------- d-----w- c:\users\jamie\appdata\local\{59CF0317-A669-4948-AD36-03953CC67D99}
2011-03-18 15:28:33 -------- d-----w- c:\users\jamie\appdata\local\{889EF7D4-E2B2-4210-98BC-562CF820C770}
2011-03-14 22:06:33 -------- d-----w- c:\program files\Free Audio Pack
2011-03-11 21:07:26 -------- d-----w- c:\users\jamie\appdata\local\{A83C51F8-9B6A-43AD-89EB-5F57B8DED0E5}
2011-03-10 10:36:22 -------- d-----w- c:\program files\iPod
2011-03-08 23:36:48 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-08 23:36:47 322560 ----a-w- c:\windows\system32\sbe.dll
2011-03-08 23:36:47 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-08 23:36:47 153088 ----a-w- c:\windows\system32\sbeio.dll
2011-03-08 23:36:46 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-03-08 23:36:46 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-07 17:00:04 -------- d-----w- c:\users\jamie\appdata\local\{08DAB889-D2D1-4BD1-B7E8-1C7D8C1AAC19}
2011-03-04 20:55:33 -------- d-----w- c:\users\jamie\appdata\local\{800BF940-4B5B-4FD4-8807-9864DD0B7800}
2011-03-03 23:08:27 -------- d-----w- c:\users\jamie\appdata\local\{0DDE6C29-0DE7-453C-AC91-583B3E84CA49}
2011-03-03 21:46:41 -------- d-----w- c:\program files\iTunes
2011-03-03 21:42:43 -------- d-----w- c:\program files\Bonjour
2011-03-02 16:23:36 -------- d-----w- c:\users\jamie\appdata\local\{5B620FEB-1A5B-4689-8F9E-2CE2B8AFC230}
.
==================== Find3M ====================
.
2011-02-18 16:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-01-31 15:52:58 626688 ----a-w- c:\windows\system32\msvcr80.dll
2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-08 08:47:50 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 ----a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 15:53:14.92 ===============
and here is my GMER log:
Quote
Rootkit scan 2011-04-01 16:31:38
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000006b SAMSUNG_ rev.CP10
Running: gmer.exe; Driver: C:\Users\Jamie\AppData\Local\Temp\ugloypod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8E2659CA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8E267EAC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8E267F04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8E26801A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8E267E02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8E267F54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8E267E56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8E267FC8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8E2659EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8E2657B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8E265A12]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8E268412]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8E2664AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8E267EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8E267F2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8E268044]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8E267E2E]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA2FD7780]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8E267F94]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8E267E84]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8E267FF2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8E266370]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8E265A36]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8E265A5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8E265812]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8E26594E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8E26592A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8E265972]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xA2FD7830]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA2FD78D0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8E265A7E]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA2FD7970]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8E98C8DE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 82ABB890 4 Bytes [CA, 59, 26, 8E]
.text ntkrnlpa.exe!KeSetEvent + 1D1 82ABB954 8 Bytes [AC, 7E, 26, 8E, 04, 7F, 26, ...]
.text ntkrnlpa.exe!KeSetEvent + 1DD 82ABB960 4 Bytes [1A, 80, 26, 8E]
.text ntkrnlpa.exe!KeSetEvent + 1F5 82ABB978 4 Bytes [02, 7E, 26, 8E]
.text ntkrnlpa.exe!KeSetEvent + 215 82ABB998 8 Bytes [54, 7F, 26, 8E, 56, 7E, 26, ...]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82BE65C7 5 Bytes JMP 8E98829E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 82C3F4F3 5 Bytes JMP 8E989D38 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82C48E18 4 Bytes CALL 8E266E3B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82C4CA8C 4 Bytes CALL 8E266E51 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82CA0DAE 7 Bytes JMP 8E98C8E2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE spsys.sys!?SPVersion@@3PADA + 1ABF 8149503F 110 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 814950AF 1 Byte [16]
PAGE spsys.sys!?SPVersion@@3PADA + 1B2F 814950AF 128 Bytes [16, 3B, C8, 75, E2, B0, 01, ...]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB0 81495130 6 Bytes [0E, 83, 78, 14, 01, 75]
PAGE spsys.sys!?SPVersion@@3PADA + 1BB7 81495137 2298 Bytes [83, 78, 18, 37, 75, 02, B3, ...]
PAGE ...
? C:\Users\Jamie\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\Mozilla Firefox\firefox.exe[268] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\Explorer.EXE[424] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00090030
.text C:\Windows\Explorer.EXE[424] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0009006C
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 000B006C
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000B00A8
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000B01D4
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000B00E4
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 000B0120
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 000B015C
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 000B0198
.text C:\Windows\Explorer.EXE[424] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 000B0030
.text C:\Windows\Explorer.EXE[424] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000C00A8
.text C:\Windows\Explorer.EXE[424] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000C00E4
.text C:\Windows\Explorer.EXE[424] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 000C0120
.text C:\Windows\Explorer.EXE[424] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 000C0030
.text C:\Windows\Explorer.EXE[424] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 000C006C
.text C:\Windows\system32\taskeng.exe[460] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\taskeng.exe[460] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\taskeng.exe[460] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\taskeng.exe[460] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Windows\system32\taskeng.exe[460] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Windows\system32\taskeng.exe[460] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Windows\system32\taskeng.exe[460] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Windows\system32\taskeng.exe[460] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\system32\Dwm.exe[604] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\Dwm.exe[604] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\Dwm.exe[604] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\Dwm.exe[604] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Windows\system32\Dwm.exe[604] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Windows\system32\Dwm.exe[604] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Windows\system32\Dwm.exe[604] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Windows\system32\Dwm.exe[604] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\system32\wininit.exe[716] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00030030
.text C:\Windows\system32\wininit.exe[716] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0003006C
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0005006C
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000500A8
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000501D4
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000500E4
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00050120
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0005015C
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00050198
.text C:\Windows\system32\wininit.exe[716] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00050030
.text C:\Windows\system32\wininit.exe[716] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000600A8
.text C:\Windows\system32\wininit.exe[716] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000600E4
.text C:\Windows\system32\wininit.exe[716] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00060120
.text C:\Windows\system32\wininit.exe[716] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00060030
.text C:\Windows\system32\wininit.exe[716] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0006006C
.text C:\Windows\system32\services.exe[760] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\services.exe[760] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\services.exe[760] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Windows\system32\services.exe[760] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Windows\system32\services.exe[760] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Windows\system32\services.exe[760] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Windows\system32\services.exe[760] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\system32\lsass.exe[776] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\lsass.exe[776] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Windows\system32\lsass.exe[776] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Windows\system32\lsass.exe[776] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Windows\system32\lsass.exe[776] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Windows\system32\lsass.exe[776] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Windows\system32\lsass.exe[776] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Windows\system32\lsass.exe[776] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Windows\system32\lsm.exe[784] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\lsm.exe[784] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\lsm.exe[784] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\winlogon.exe[828] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00030030
.text C:\Windows\system32\winlogon.exe[828] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0003006C
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0005006C
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000500A8
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000501D4
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000500E4
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00050120
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0005015C
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00050198
.text C:\Windows\system32\winlogon.exe[828] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00050030
.text C:\Windows\system32\winlogon.exe[828] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000600A8
.text C:\Windows\system32\winlogon.exe[828] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000600E4
.text C:\Windows\system32\winlogon.exe[828] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00060120
.text C:\Windows\system32\winlogon.exe[828] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00060030
.text C:\Windows\system32\winlogon.exe[828] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0006006C
.text C:\Windows\System32\spoolsv.exe[868] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\System32\spoolsv.exe[868] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\System32\spoolsv.exe[868] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\System32\spoolsv.exe[868] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 002100A8
.text C:\Windows\System32\spoolsv.exe[868] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 002100E4
.text C:\Windows\System32\spoolsv.exe[868] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00210120
.text C:\Windows\System32\spoolsv.exe[868] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00210030
.text C:\Windows\System32\spoolsv.exe[868] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0021006C
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[1004] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\nvvsvc.exe[1056] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Windows\system32\nvvsvc.exe[1056] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Windows\system32\nvvsvc.exe[1056] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0008006C
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000800A8
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000801D4
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000800E4
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00080120
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0008015C
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00080198
.text C:\Windows\system32\svchost.exe[1088] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00080030
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001500A8
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001500E4
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00150120
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00150030
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0015006C
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Windows\system32\wbem\wmiprvse.exe[1140] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000D00A8
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000D00E4
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 000D0120
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 000D0030
.text C:\Windows\system32\svchost.exe[1184] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 000D006C
.text C:\Windows\System32\svchost.exe[1220] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00090030
.text C:\Windows\System32\svchost.exe[1220] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0009006C
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 000B006C
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000B00A8
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000B01D4
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000B00E4
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 000B0120
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 000B015C
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 000B0198
.text C:\Windows\System32\svchost.exe[1220] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 000B0030
.text C:\Windows\System32\svchost.exe[1220] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001200A8
.text C:\Windows\System32\svchost.exe[1220] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001200E4
.text C:\Windows\System32\svchost.exe[1220] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00120120
.text C:\Windows\System32\svchost.exe[1220] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00120030
.text C:\Windows\System32\svchost.exe[1220] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0012006C
.text C:\Windows\System32\svchost.exe[1256] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\System32\svchost.exe[1256] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\System32\svchost.exe[1256] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\System32\svchost.exe[1256] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 002000A8
.text C:\Windows\System32\svchost.exe[1256] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 002000E4
.text C:\Windows\System32\svchost.exe[1256] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00200120
.text C:\Windows\System32\svchost.exe[1256] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00200030
.text C:\Windows\System32\svchost.exe[1256] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0020006C
.text C:\Windows\system32\svchost.exe[1292] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1292] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\svchost.exe[1292] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000C00A8
.text C:\Windows\system32\svchost.exe[1292] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000C00E4
.text C:\Windows\system32\svchost.exe[1292] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 000C0120
.text C:\Windows\system32\svchost.exe[1292] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 000C0030
.text C:\Windows\system32\svchost.exe[1292] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 000C006C
.text C:\Windows\system32\taskeng.exe[1400] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\taskeng.exe[1400] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\taskeng.exe[1400] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\taskeng.exe[1400] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Windows\system32\taskeng.exe[1400] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Windows\system32\taskeng.exe[1400] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Windows\system32\taskeng.exe[1400] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Windows\system32\taskeng.exe[1400] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\system32\svchost.exe[1424] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1424] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[1424] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\svchost.exe[1472] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1472] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[1472] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\svchost.exe[1472] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001B00A8
.text C:\Windows\system32\svchost.exe[1472] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001B00E4
.text C:\Windows\system32\svchost.exe[1472] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 001B0120
.text C:\Windows\system32\svchost.exe[1472] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 001B0030
.text C:\Windows\system32\svchost.exe[1472] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 001B006C
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0027006C
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 002700A8
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 002701D4
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 002700E4
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00270120
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0027015C
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00270198
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00270030
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 002800A8
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 002800E4
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00280120
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00280030
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1572] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0028006C
.text C:\Windows\system32\nvvsvc.exe[1596] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Windows\system32\nvvsvc.exe[1596] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0027006C
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 002700A8
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 002701D4
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 002700E4
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00270120
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0027015C
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00270198
.text C:\Windows\system32\nvvsvc.exe[1596] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00270030
.text C:\Windows\system32\nvvsvc.exe[1596] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 002800A8
.text C:\Windows\system32\nvvsvc.exe[1596] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 002800E4
.text C:\Windows\system32\nvvsvc.exe[1596] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00280120
.text C:\Windows\system32\nvvsvc.exe[1596] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00280030
.text C:\Windows\system32\nvvsvc.exe[1596] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0028006C
.text C:\Windows\system32\svchost.exe[1780] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[1780] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[1780] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\svchost.exe[1780] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000C00A8
.text C:\Windows\system32\svchost.exe[1780] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000C00E4
.text C:\Windows\system32\svchost.exe[1780] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 000C0120
.text C:\Windows\system32\svchost.exe[1780] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 000C0030
.text C:\Windows\system32\svchost.exe[1780] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 000C006C
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1960] kernel32.dll!SetUnhandledExceptionFilter 75D6A84F 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe[1980] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\wbem\unsecapp.exe[2356] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\wbem\unsecapp.exe[2356] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Windows\system32\wbem\unsecapp.exe[2356] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Windows\system32\wbem\unsecapp.exe[2356] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Windows\system32\wbem\unsecapp.exe[2356] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Windows\system32\wbem\unsecapp.exe[2356] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Windows\SOUNDMAN.EXE[2380] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00140030
.text C:\Windows\SOUNDMAN.EXE[2380] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0014006C
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0016006C
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001600A8
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001601D4
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001600E4
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00160120
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0016015C
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00160198
.text C:\Windows\SOUNDMAN.EXE[2380] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00160030
.text C:\Windows\SOUNDMAN.EXE[2380] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001700A8
.text C:\Windows\SOUNDMAN.EXE[2380] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001700E4
.text C:\Windows\SOUNDMAN.EXE[2380] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00170120
.text C:\Windows\SOUNDMAN.EXE[2380] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00170030
.text C:\Windows\SOUNDMAN.EXE[2380] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0017006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2400] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\AVG\AVG10\avgwdsvc.exe[2440] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\Bonjour\mDNSResponder.exe[2464] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00240030
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0024006C
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0026006C
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 002600A8
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 002601D4
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 002600E4
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00260120
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0026015C
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00260198
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00260030
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 002700A8
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 002700E4
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00270120
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00270030
.text C:\Program Files\Hotspot Shield\bin\openvpnas.exe[2500] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0027006C
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 00C700A8
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 00C700E4
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00C70120
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00C70030
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 00C7006C
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\AVG\AVG10\avgtray.exe[2632] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001900A8
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001900E4
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00190120
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00190030
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0019006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 001A006C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001A00A8
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001A01D4
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001A00E4
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 001A0120
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 001A015C
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 001A0198
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2728] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 001A0030
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe[2784] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0008006C
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000800A8
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000801D4
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000800E4
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00080120
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0008015C
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00080198
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00080030
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000900A8
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000900E4
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00090120
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00090030
.text C:\Program Files\Windows Sidebar\sidebar.exe[2828] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0009006C
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe[2836] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\Hotspot Shield\bin\hsswd.exe[2844] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\mysql\bin\mysqld-nt.exe[2920] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00140030
.text C:\mysql\bin\mysqld-nt.exe[2920] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0014006C
.text C:\mysql\bin\mysqld-nt.exe[2920] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001600A8
.text C:\mysql\bin\mysqld-nt.exe[2920] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001600E4
.text C:\mysql\bin\mysqld-nt.exe[2920] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00160120
.text C:\mysql\bin\mysqld-nt.exe[2920] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00160030
.text C:\mysql\bin\mysqld-nt.exe[2920] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0016006C
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\mysql\bin\mysqld-nt.exe[2920] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\iTunes\iTunesHelper.exe[2940] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0008006C
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000800A8
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000801D4
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000800E4
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00080120
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0008015C
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00080198
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00080030
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000900A8
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000900E4
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00090120
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00090030
.text C:\Program Files\Windows Sidebar\sidebar.exe[3064] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0009006C
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[3084] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0017006C
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001700A8
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001701D4
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001700E4
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00170120
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0017015C
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00170198
.text C:\Program Files\iPod\bin\iPodService.exe[3112] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00170030
.text C:\Program Files\iPod\bin\iPodService.exe[3112] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001800A8
.text C:\Program Files\iPod\bin\iPodService.exe[3112] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001800E4
.text C:\Program Files\iPod\bin\iPodService.exe[3112] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00180120
.text C:\Program Files\iPod\bin\iPodService.exe[3112] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00180030
.text C:\Program Files\iPod\bin\iPodService.exe[3112] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0018006C
.text C:\Windows\system32\svchost.exe[3196] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[3196] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[3196] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Windows\System32\svchost.exe[3248] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\System32\svchost.exe[3248] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\System32\svchost.exe[3248] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0008006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000800A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000801D4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000800E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00080120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0008015C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00080198
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00080030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000900A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000900E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00090120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00090030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3288] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0009006C
.text C:\Windows\system32\SearchIndexer.exe[3416] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 000D0030
.text C:\Windows\system32\SearchIndexer.exe[3416] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 000D006C
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 000F006C
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000F00A8
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000F01D4
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000F00E4
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 000F0120
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 000F015C
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 000F0198
.text C:\Windows\system32\SearchIndexer.exe[3416] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 000F0030
.text C:\Windows\system32\SearchIndexer.exe[3416] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001000A8
.text C:\Windows\system32\SearchIndexer.exe[3416] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001000E4
.text C:\Windows\system32\SearchIndexer.exe[3416] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00100120
.text C:\Windows\system32\SearchIndexer.exe[3416] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00100030
.text C:\Windows\system32\SearchIndexer.exe[3416] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0010006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00090030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0009006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 000B006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000B00A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000B01D4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000B00E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 000B0120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 000B015C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 000B0198
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 000B0030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000C00A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000C00E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 000C0120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 000C0030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3520] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 000C006C
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001700A8
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001700E4
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00170120
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00170030
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0017006C
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0018006C
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 001800A8
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 001801D4
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 001800E4
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00180120
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0018015C
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00180198
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3844] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00180030
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00040030
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0004006C
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000D00A8
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000D00E4
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 000D0120
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 000D0030
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 000D006C
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 000E006C
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000E00A8
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000E01D4
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000E00E4
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 000E0120
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 000E015C
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 000E0198
.text C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe[4556] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 000E0030
.text C:\Windows\system32\svchost.exe[4592] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Windows\system32\svchost.exe[4592] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Windows\system32\svchost.exe[4592] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\iTunes\iTunes.exe[4748] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\iTunes\iTunes.exe[4748] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\iTunes\iTunes.exe[4748] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\iTunes\iTunes.exe[4748] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 000800A8
.text C:\Program Files\iTunes\iTunes.exe[4748] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 000800E4
.text C:\Program Files\iTunes\iTunes.exe[4748] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00080120
.text C:\Program Files\iTunes\iTunes.exe[4748] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00080030
.text C:\Program Files\iTunes\iTunes.exe[4748] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0008006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00050030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0005006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0007006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 000700A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 000701D4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 000700E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00070120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0007015C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00070198
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00070030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 001900A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 001900E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00190120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00190030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe[5248] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0019006C
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ntdll.dll!LdrLoadDll 77BC93A8 5 Bytes JMP 00150030
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ntdll.dll!LdrUnloadDll 77BDB740 5 Bytes JMP 0015006C
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!CreateServiceW 75FD9EB4 5 Bytes JMP 0026006C
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!DeleteService 75FDA07E 5 Bytes JMP 002600A8
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!SetServiceObjectSecurity 76016CD9 5 Bytes JMP 002601D4
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!ChangeServiceConfigA 76016DD9 5 Bytes JMP 002600E4
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!ChangeServiceConfigW 76016F81 5 Bytes JMP 00260120
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!ChangeServiceConfig2A 76017099 5 Bytes JMP 0026015C
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!ChangeServiceConfig2W 760171E1 5 Bytes JMP 00260198
.text C:\Users\Jamie\Desktop\gmer.exe[5432] ADVAPI32.dll!CreateServiceA 760172A1 5 Bytes JMP 00260030
.text C:\Users\Jamie\Desktop\gmer.exe[5432] USER32.dll!SetWindowsHookExA 75A06322 5 Bytes JMP 002700A8
.text C:\Users\Jamie\Desktop\gmer.exe[5432] USER32.dll!SetWindowsHookExW 75A087AD 5 Bytes JMP 002700E4
.text C:\Users\Jamie\Desktop\gmer.exe[5432] USER32.dll!UnhookWindowsHookEx 75A098DB 5 Bytes JMP 00270120
.text C:\Users\Jamie\Desktop\gmer.exe[5432] USER32.dll!SetWinEventHook 75A09F3A 5 Bytes JMP 00270030
.text C:\Users\Jamie\Desktop\gmer.exe[5432] USER32.dll!UnhookWinEvent 75A0C06F 5 Bytes JMP 0027006C
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
---- EOF - GMER 1.0.15 ----
This post has been edited by FRISC0: 01 April 2011 - 10:34 AM

Help
This topic is locked


Back to top



, clicking Control Panel, clicking Appearance and Personalization, and then clicking Folder Options.
button.
to download the ESET Smart Installer. Save it to your desktop.
button.












