GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-25 21:35:51
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 TOSHIBA_MK1031GAS rev.AA204A
Running: gmer.exe; Driver: C:\DOCUME~1\MR5D72~1.NAT\LOCALS~1\Temp\pxtdrpog.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAllocateVirtualMemory [0xAFCCB328]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAssignProcessToJobObject [0xAFCCA824]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwConnectPort [0xAFCC964C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateFile [0xAFCD01F8]
SSDT BA75A646 ZwCreateKey
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreatePort [0xAFCC946A]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcess [0xAFCCADE4]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcessEx [0xAFCC7978]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateSection [0xAFCC74F2]
SSDT BA75A63C ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDebugActiveProcess [0xAFCC8D22]
SSDT BA75A64B ZwDeleteKey
SSDT BA75A655 ZwDeleteValueKey
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDuplicateObject [0xAFCC932C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadDriver [0xAFCCA24C]
SSDT BA75A65A ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenFile [0xAFCD0554]
SSDT BA75A628 ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenSection [0xAFCC77B4]
SSDT BA75A62D ZwOpenThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwProtectVirtualMemory [0xAFCCA5D6]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwQueueApcThread [0xAFCCA940]
SSDT BA75A664 ZwReplaceKey
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestPort [0xAFCC9CB0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestWaitReplyPort [0xAFCC9F14]
SSDT BA75A65F ZwRestoreKey
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwResumeThread [0xAFCC90CE]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSecureConnectPort [0xAFCC986E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetContextThread [0xAFCC8BCC]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetSystemInformation [0xAFCCAFDC]
SSDT BA75A650 ZwSetValueKey
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwShutdownSystem [0xAFCCA186]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendProcess [0xAFCC91FE]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendThread [0xAFCC8F7A]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSystemDebugControl [0xAFCC8E40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateProcess [0xAFCC8472]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateThread [0xAFCC8A66]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwUnloadDriver [0xAFCCA414]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwWriteVirtualMemory [0xAFCCA700]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 243C 80501C74 12 Bytes [6A, 94, CC, AF, E4, AD, CC, ...] {PUSH -0x6c; INT 3 ; SCASD ; IN AL, 0xad; INT 3 ; SCASD ; JS 0x83; INT 3 ; SCASD }
.text ntkrnlpa.exe!ZwCallbackReturn + 2778 80501FB0 12 Bytes [FE, 91, CC, AF, 7A, 8F, CC, ...]
? C:\DOCUME~1\MR5D72~1.NAT\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[136] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[136] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\Explorer.EXE[136] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[136] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [7A, 71] {JP 0x73}
.text C:\WINDOWS\Explorer.EXE[136] kernel32.dll!LoadLibraryExW + C4 7C801BB9 2 Bytes CALL 00810001
.text C:\WINDOWS\Explorer.EXE[136] kernel32.dll!LoadLibraryExW + C7 7C801BBC 1 Byte [84]
.text C:\WINDOWS\Explorer.EXE[136] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71780F5A
.text C:\WINDOWS\Explorer.EXE[136] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\Explorer.EXE[136] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\Explorer.EXE[136] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 71750F5A
.text C:\WINDOWS\Explorer.EXE[136] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[136] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [8F, 71]
.text C:\WINDOWS\Explorer.EXE[136] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\Explorer.EXE[136] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 71930F5A
.text C:\WINDOWS\Explorer.EXE[136] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[136] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [8C, 71]
.text C:\WINDOWS\Explorer.EXE[136] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 71840F5A
.text C:\WINDOWS\Explorer.EXE[136] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 71810F5A
.text C:\WINDOWS\Explorer.EXE[136] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 718A0F5A
.text C:\WINDOWS\Explorer.EXE[136] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71870F5A
.text C:\WINDOWS\Explorer.EXE[136] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71990F5A
.text C:\WINDOWS\Explorer.EXE[136] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71960F5A
.text C:\WINDOWS\Explorer.EXE[136] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\Explorer.EXE[136] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [6E, 71]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [6B, 71]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ntdll.dll!LdrGetProcedureAddress 7C917CF0 6 Bytes JMP 71630F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 71600F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AB0001
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71690F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 715D0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 718D0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 71660F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71900F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [80, 71]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 71840F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 71750F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 71720F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 717B0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71780F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 718A0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71870F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ole32.dll!CoCreateInstanceEx 774FF154 6 Bytes JMP 71960F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ole32.dll!CoCreateInstance 774FF1AC 6 Bytes JMP 71990F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] ole32.dll!CoGetClassObject 775151F5 6 Bytes JMP 71930F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Documents and Settings\Mr. Nation\Desktop\gmer\gmer.exe[204] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Online Armor\oasrv.exe[1176] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00DC0001
.text C:\Program Files\Online Armor\oasrv.exe[1176] kernel32.dll!CreateRemoteThread + 174 7C810640 4 Bytes JMP 71A20000
.text C:\Program Files\Online Armor\oasrv.exe[1176] user32.dll!LoadStringW 7E419E36 6 Bytes JMP 71A50F5A
.text C:\Program Files\Online Armor\oasrv.exe[1176] user32.dll!LoadStringA 7E42C908 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Online Armor\OAhlp.exe[2244] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F60001
.text C:\Program Files\Online Armor\OAhlp.exe[2244] user32.dll!LoadStringW 7E419E36 6 Bytes JMP 71A50F5A
.text C:\Program Files\Online Armor\OAhlp.exe[2244] user32.dll!LoadStringA 7E42C908 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00920001
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 1068EDA6 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 1068ED38 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 104A5451 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 104A5A99 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2324] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00401410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009F0001
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!sendto 71AB2F51 6 Bytes JMP 715A0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!select 71AB30A8 6 Bytes JMP 71570F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!closesocket 71AB3E2B 6 Bytes JMP 71660F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!ioctlsocket 71AB3F50 6 Bytes JMP 71540F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 71630F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!send 71AB4C27 6 Bytes JMP 715D0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!WSARecv 71AB4CB5 6 Bytes JMP 71480F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!recv 71AB676F 6 Bytes JMP 714C0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!WSASend 71AB68FA 6 Bytes JMP 71450F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] WS2_32.dll!WSAAsyncSelect 71AC0991 6 Bytes JMP 71510F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2672] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AA0001
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3188] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Rundll32.exe[3224] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\WINDOWS\system32\Rundll32.exe[3224] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Rundll32.exe[3224] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!LoadLibraryExW + C4 7C801BB9 2 Bytes CALL 00810001
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!LoadLibraryExW + C7 7C801BBC 1 Byte [84]
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Rundll32.exe[3224] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\WINDOWS\system32\Rundll32.exe[3224] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Rundll32.exe[3224] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\WINDOWS\system32\Rundll32.exe[3224] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\system32\Rundll32.exe[3224] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\keyhook.exe[3252] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\WINDOWS\system32\keyhook.exe[3252] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\keyhook.exe[3252] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009F0001
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\keyhook.exe[3252] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\WINDOWS\system32\keyhook.exe[3252] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\keyhook.exe[3252] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\WINDOWS\system32\keyhook.exe[3252] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\system32\keyhook.exe[3252] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Launch Manager\QtZgAcer.EXE[3332] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\WLTRAY.exe[3400] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\WINDOWS\system32\WLTRAY.exe[3400] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\WLTRAY.exe[3400] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\WLTRAY.exe[3400] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\WINDOWS\system32\WLTRAY.exe[3400] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\WLTRAY.exe[3400] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\WINDOWS\system32\WLTRAY.exe[3400] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\system32\WLTRAY.exe[3400] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[3432] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\WINDOWS\AGRSMMSG.exe[3432] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[3432] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A00001
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[3432] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\WINDOWS\AGRSMMSG.exe[3432] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[3432] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\WINDOWS\AGRSMMSG.exe[3432] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\AGRSMMSG.exe[3432] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\SOUNDMAN.EXE[3584] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\WINDOWS\SOUNDMAN.EXE[3584] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\SOUNDMAN.EXE[3584] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A00001
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\SOUNDMAN.EXE[3584] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\WINDOWS\SOUNDMAN.EXE[3584] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\SOUNDMAN.EXE[3584] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\WINDOWS\SOUNDMAN.EXE[3584] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\SOUNDMAN.EXE[3584] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3628] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Online Armor\oaui.exe[3656] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F70001
.text C:\Program Files\Online Armor\oaui.exe[3656] user32.dll!LoadStringW 7E419E36 6 Bytes JMP 71A50F5A
.text C:\Program Files\Online Armor\oaui.exe[3656] user32.dll!LoadStringA 7E42C908 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3692] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A40001
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3736] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A00001
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe[3764] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B20001
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!sendto 71AB2F51 6 Bytes JMP 71600F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!select 71AB30A8 6 Bytes JMP 715D0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!closesocket 71AB3E2B 6 Bytes JMP 716C0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!ioctlsocket 71AB3F50 6 Bytes JMP 715A0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 71690F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!send 71AB4C27 6 Bytes JMP 71630F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!WSARecv 71AB4CB5 6 Bytes JMP 714E0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!recv 71AB676F 6 Bytes JMP 71520F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!WSASend 71AB68FA 6 Bytes JMP 714B0F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] WS2_32.dll!WSAAsyncSelect 71AC0991 6 Bytes JMP 71570F5A
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[3792] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\sistray.exe[4040] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\WINDOWS\system32\sistray.exe[4040] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\sistray.exe[4040] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A40001
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\WINDOWS\system32\sistray.exe[4040] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\sistray.exe[4040] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\WINDOWS\system32\sistray.exe[4040] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\sistray.exe[4040] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\WINDOWS\system32\sistray.exe[4040] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] GDI32.dll!BitBlt 77F16F79 6 Bytes JMP 717B0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] GDI32.dll!CreateDCA 77F1B7D2 6 Bytes JMP 71840F5A
.text C:\WINDOWS\system32\sistray.exe[4040] GDI32.dll!CreateDCW 77F1BE38 6 Bytes JMP 71810F5A
.text C:\WINDOWS\system32\sistray.exe[4040] advapi32.dll!CreateServiceA 77E37211 6 Bytes JMP 71930F5A
.text C:\WINDOWS\system32\sistray.exe[4040] advapi32.dll!CreateServiceW 77E373A9 6 Bytes JMP 71900F5A
.text C:\WINDOWS\system32\sistray.exe[4040] WS2_32.dll!socket 71AB4211 6 Bytes JMP 71AF0F5A
.text C:\WINDOWS\system32\sistray.exe[4040] IPHLPAPI.DLL!IcmpSendEcho2 76D6B73C 6 Bytes JMP 719C0F5A
---- Devices - GMER 1.0.15 ----
Device \Driver\Tcpip \Device\Ip OAmon.sys (TDI Helper Driver/Emsisoft)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
Device \Driver\Tcpip \Device\Tcp OAmon.sys (TDI Helper Driver/Emsisoft)
Device \Driver\Tcpip \Device\Udp OAmon.sys (TDI Helper Driver/Emsisoft)
Device \Driver\Tcpip \Device\RawIp OAmon.sys (TDI Helper Driver/Emsisoft)
Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys (TDI Helper Driver/Emsisoft)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x05 0x73 0x21 0xDD ...
---- EOF - GMER 1.0.15 ----
When I tried to attach the ark.txt file, as mentioned on the prep guide page, I got an error stating that I wasn't "permitted to upload this kind of file". I also tried renaming the ark file and zipping as well, obviously neither of those worked. Please let me know if I'm doing something incorrectly, or what the next step is. Thanks in advance!
I also should note that after reading a few of these posts, I was alerted to the fact that I was running a very old adobe reader 7. So just before I started the steps to post on here, I did uninstall 7 and replace it with 10.
EDIT: Posts merged ~Budapest
Attached File(s)
-
attach.txt (14.08K)
Number of downloads: 0
This post has been edited by Budapest: 26 June 2011 - 06:09 PM

Help
This topic is locked

Back to top












