GMER 1.0.15.15640 -
http://www.gmer.net
Rootkit scan 2011-06-15 01:49:16
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS723225A7A364 rev.ECBOA60W
Running: deh8bqnr.exe; Driver: C:\Users\DiKi\AppData\Local\Temp\kxldapod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8EA4C202]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8F09FCB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8EA4E81C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8EA4E874]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8EA4E98A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8EA4E772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8EA4E8C4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8EA4E7C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8EA4E938]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8EA4C226]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8F09FD62]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8EA4BFF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8EA4C24A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8EA4ED82]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8EA4CCDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8EA4E84C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8EA4E89C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8EA4E9B4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8EA4E79E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8EA4E904]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8EA4E7F4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8EA4E962]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8F09FDFA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8EA4CBA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8EA4C26E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8EA4C292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8EA4C04A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8EA4C186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8EA4C162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8EA4C1AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8EA4C2B6]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A93579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AB7F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 214 82ABF714 4 Bytes [02, C2, A4, 8E]
.text ntkrnlpa.exe!RtlSidHashLookup + 23C 82ABF73C 4 Bytes [B2, FC, 09, 8F]
.text ntkrnlpa.exe!RtlSidHashLookup + 2F0 82ABF7F0 8 Bytes [1C, E8, A4, 8E, 74, E8, A4, ...]
.text ntkrnlpa.exe!RtlSidHashLookup + 2FC 82ABF7FC 4 Bytes [8A, E9, A4, 8E]
.text ntkrnlpa.exe!RtlSidHashLookup + 318 82ABF818 4 Bytes [72, E7, A4, 8E]
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82CBD0EA 4 Bytes CALL 8EA4D34B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82CC51C5 4 Bytes CALL 8EA4D361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8F80D000, 0x353030, 0xE8000020]
.text win32k.sys!EngMultiByteToUnicodeN + 7240 95219869 5 Bytes JMP 8EA4F342 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngIsSemaphoreOwned + 8A1B 9523086D 5 Bytes JMP 8EA4F46C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngEraseSurface + BF73 95251442 5 Bytes JMP 8EA4FE38 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 3318 95264C55 5 Bytes JMP 8EA4EF60 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 401D 9526595A 5 Bytes JMP 8EA4FC04 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCTGetGammaTable + 177B 9526B28B 5 Bytes JMP 8EA4F352 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + 7A2D 9528782C 5 Bytes JMP 8EA4EFD0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + 8714 95288513 5 Bytes JMP 8EA4EE84 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + 9311 95289110 5 Bytes JMP 8EA4F1AC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateSemaphore + A7EB 952A3FDB 5 Bytes JMP 8EA4FB90 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateSemaphore + CB9D 952A638D 5 Bytes JMP 8EA4EDB8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngBitBlt + 56E 952AF939 5 Bytes JMP 8EA4FBDA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngBitBlt + 5201 952B45CC 5 Bytes JMP 8EA50040 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLpkInstalled + 6119 952C7842 5 Bytes JMP 8EA4EE9C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLpkInstalled + 1AE7F 952DC5A8 5 Bytes JMP 8EA4FC1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_bEnum + 9767 952EFA7F 5 Bytes JMP 8EA4F114 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 26C1 952F7B45 5 Bytes JMP 8EA4FEF6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bPolyBezierTo + F8 9530B449 5 Bytes JMP 8EA4F0DA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngAcquireSemaphoreSharedNoWait + 1F5A 9531B437 5 Bytes JMP 8EA4FF9E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_vGetBounds + EB5 95345C7F 5 Bytes JMP 8EA4F034 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCTGetCurrentGamma + 1C7A 95349C9C 5 Bytes JMP 8EA4F06A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngSetPointerShape + C86 9534C919 5 Bytes JMP 8EA4FD80 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_cEnumStart + 6CE0 953555A5 5 Bytes JMP 8EA4EF1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 9E245000 234 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 507B 9E2450EB 55 Bytes [9E, 56, BE, 20, 05, 24, 9E, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 9E245123 629 Bytes [05, 24, 9E, FE, 05, 34, 05, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 9E245399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F 9E2453FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\csrss.exe[356] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\wininit.exe[432] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[432] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[432] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\wininit.exe[432] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 000D0A08
.text C:\Windows\system32\wininit.exe[432] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 000D03FC
.text C:\Windows\system32\wininit.exe[432] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 000D0804
.text C:\Windows\system32\wininit.exe[432] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 000D01F8
.text C:\Windows\system32\wininit.exe[432] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 000D0600
.text C:\Windows\system32\csrss.exe[440] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\services.exe[488] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\services.exe[488] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\services.exe[488] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\lsass.exe[504] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[504] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[504] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\lsm.exe[512] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsm.exe[512] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsm.exe[512] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[540] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[540] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[540] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[540] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00060A08
.text C:\Windows\system32\winlogon.exe[540] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 000603FC
.text C:\Windows\system32\winlogon.exe[540] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00060804
.text C:\Windows\system32\winlogon.exe[540] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 000601F8
.text C:\Windows\system32\winlogon.exe[540] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00060600
.text C:\Windows\system32\svchost.exe[652] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[652] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[652] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[796] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Windows\system32\atiesrxx.exe[796] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Windows\system32\atiesrxx.exe[796] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[796] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atiesrxx.exe[796] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atiesrxx.exe[796] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Windows\system32\atiesrxx.exe[796] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atiesrxx.exe[796] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Windows\System32\svchost.exe[872] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[872] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[872] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\System32\svchost.exe[872] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00210A08
.text C:\Windows\System32\svchost.exe[872] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 002103FC
.text C:\Windows\System32\svchost.exe[872] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00210804
.text C:\Windows\System32\svchost.exe[872] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 002101F8
.text C:\Windows\System32\svchost.exe[872] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00210600
.text C:\Windows\System32\svchost.exe[928] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[928] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[928] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\System32\svchost.exe[928] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00430A08
.text C:\Windows\System32\svchost.exe[928] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 004303FC
.text C:\Windows\System32\svchost.exe[928] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00430804
.text C:\Windows\System32\svchost.exe[928] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 004301F8
.text C:\Windows\System32\svchost.exe[928] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00430600
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[972] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00E20A08
.text C:\Windows\system32\svchost.exe[972] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 00E203FC
.text C:\Windows\system32\svchost.exe[972] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00E20804
.text C:\Windows\system32\svchost.exe[972] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 00E201F8
.text C:\Windows\system32\svchost.exe[972] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00E20600
.text C:\Program Files\IDT\WDM\STacSV.exe[996] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\IDT\WDM\STacSV.exe[996] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\IDT\WDM\STacSV.exe[996] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\IDT\WDM\STacSV.exe[996] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00300A08
.text C:\Program Files\IDT\WDM\STacSV.exe[996] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 003003FC
.text C:\Program Files\IDT\WDM\STacSV.exe[996] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00300804
.text C:\Program Files\IDT\WDM\STacSV.exe[996] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 003001F8
.text C:\Program Files\IDT\WDM\STacSV.exe[996] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00300600
.text C:\Windows\system32\AUDIODG.EXE[1104] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1172] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00320A08
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 003203FC
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00320804
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 003201F8
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00320600
.text C:\Windows\system32\atieclxx.exe[1272] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Windows\system32\atieclxx.exe[1272] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Windows\system32\atieclxx.exe[1272] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\atieclxx.exe[1272] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atieclxx.exe[1272] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atieclxx.exe[1272] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Windows\system32\atieclxx.exe[1272] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atieclxx.exe[1272] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1372] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[1444] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[1444] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[1444] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[1444] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[1444] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[1444] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[1444] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[1444] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 000E0600
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1484] kernel32.dll!SetUnhandledExceptionFilter 770E3142 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1484] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text D:\DOWNLOADS\deh8bqnr.exe[1572] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text D:\DOWNLOADS\deh8bqnr.exe[1572] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text D:\DOWNLOADS\deh8bqnr.exe[1572] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text D:\DOWNLOADS\deh8bqnr.exe[1572] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00220A08
.text D:\DOWNLOADS\deh8bqnr.exe[1572] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 002203FC
.text D:\DOWNLOADS\deh8bqnr.exe[1572] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00220804
.text D:\DOWNLOADS\deh8bqnr.exe[1572] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 002201F8
.text D:\DOWNLOADS\deh8bqnr.exe[1572] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00220600
.text C:\Windows\system32\Dwm.exe[1612] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[1612] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[1612] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[1612] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 000F0A08
.text C:\Windows\system32\Dwm.exe[1612] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 000F03FC
.text C:\Windows\system32\Dwm.exe[1612] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 000F0804
.text C:\Windows\system32\Dwm.exe[1612] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 000F01F8
.text C:\Windows\system32\Dwm.exe[1612] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 000F0600
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1636] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Windows\Explorer.EXE[1664] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[1664] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[1664] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\Explorer.EXE[1664] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 000A0A08
.text C:\Windows\Explorer.EXE[1664] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 000A03FC
.text C:\Windows\Explorer.EXE[1664] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 000A0804
.text C:\Windows\Explorer.EXE[1664] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 000A01F8
.text C:\Windows\Explorer.EXE[1664] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 000A0600
.text C:\Program Files\IDT\WDM\sttray.exe[1768] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\IDT\WDM\sttray.exe[1768] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\IDT\WDM\sttray.exe[1768] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\IDT\WDM\sttray.exe[1768] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\IDT\WDM\sttray.exe[1768] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Program Files\IDT\WDM\sttray.exe[1768] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Program Files\IDT\WDM\sttray.exe[1768] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Program Files\IDT\WDM\sttray.exe[1768] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1776] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[1800] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe[1812] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Program Files\IDT\WDM\aestsrv.exe[1820] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\IDT\WDM\aestsrv.exe[1820] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\IDT\WDM\aestsrv.exe[1820] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1828] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\System32\spoolsv.exe[1828] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\System32\spoolsv.exe[1828] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1828] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00100A08
.text C:\Windows\System32\spoolsv.exe[1828] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001003FC
.text C:\Windows\System32\spoolsv.exe[1828] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00100804
.text C:\Windows\System32\spoolsv.exe[1828] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001001F8
.text C:\Windows\System32\spoolsv.exe[1828] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00100600
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000A03FC
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000A01F8
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00150A08
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001503FC
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00150804
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001501F8
.text C:\Program Files\Windows Sidebar\sidebar.exe[1840] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00150600
.text C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe[1948] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe[1948] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe[1948] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1968] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1968] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1968] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1968] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00210A08
.text C:\Windows\system32\svchost.exe[1968] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 002103FC
.text C:\Windows\system32\svchost.exe[1968] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00210804
.text C:\Windows\system32\svchost.exe[1968] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 002101F8
.text C:\Windows\system32\svchost.exe[1968] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00210600
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00100A08
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001003FC
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00100804
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001001F8
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2096] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00100600
.text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[2304] KERNEL32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2560] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2560] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2560] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2560] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 003F0A08
.text C:\Windows\system32\svchost.exe[2560] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 003F03FC
.text C:\Windows\system32\svchost.exe[2560] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 003F0804
.text C:\Windows\system32\svchost.exe[2560] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 003F01F8
.text C:\Windows\system32\svchost.exe[2560] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 003F0600
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00100A08
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001003FC
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00100804
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001001F8
.text C:\Windows\system32\wbem\wmiprvse.exe[2664] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00100600
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2748] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 001F0600
.text C:\Windows\system32\SearchIndexer.exe[2788] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\SearchIndexer.exe[2788] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000A01F8
.text C:\Windows\system32\SearchIndexer.exe[2788] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[2788] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00240A08
.text C:\Windows\system32\SearchIndexer.exe[2788] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 002403FC
.text C:\Windows\system32\SearchIndexer.exe[2788] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00240804
.text C:\Windows\system32\SearchIndexer.exe[2788] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 002401F8
.text C:\Windows\system32\SearchIndexer.exe[2788] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00240600
.text C:\Windows\system32\svchost.exe[3052] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[3052] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[3052] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\System32\svchost.exe[3280] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[3280] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[3280] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\System32\svchost.exe[3280] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00190A08
.text C:\Windows\System32\svchost.exe[3280] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001903FC
.text C:\Windows\System32\svchost.exe[3280] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00190804
.text C:\Windows\System32\svchost.exe[3280] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001901F8
.text C:\Windows\System32\svchost.exe[3280] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00190600
.text C:\Windows\system32\sppsvc.exe[3404] ntdll.dll!LdrUnloadDll 7736BE7F 5 Bytes JMP 000703FC
.text C:\Windows\system32\sppsvc.exe[3404] ntdll.dll!LdrLoadDll 7736F585 5 Bytes JMP 000701F8
.text C:\Windows\system32\sppsvc.exe[3404] kernel32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Windows\system32\sppsvc.exe[3404] USER32.dll!UnhookWindowsHookEx 75D8CC7B 5 Bytes JMP 00150A08
.text C:\Windows\system32\sppsvc.exe[3404] USER32.dll!UnhookWinEvent 75D8D924 5 Bytes JMP 001503FC
.text C:\Windows\system32\sppsvc.exe[3404] USER32.dll!SetWindowsHookExW 75D9210A 5 Bytes JMP 00150804
.text C:\Windows\system32\sppsvc.exe[3404] USER32.dll!SetWinEventHook 75D9507E 5 Bytes JMP 001501F8
.text C:\Windows\system32\sppsvc.exe[3404] USER32.dll!SetWindowsHookExA 75DB6DFA 5 Bytes JMP 00150600
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3624] KERNEL32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3708] KERNEL32.dll!GetBinaryTypeW + 70 770F7964 1 Byte [62]
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device \Driver\ACPI_HAL \Device\00000049 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----