Here are the results of the GMER scan
GMER 1.0.15.15640 -
http://www.gmer.net
Rootkit scan 2011-07-03 18:41:14
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 TOSHIBA_MK3263GSX rev.FG020M
Running: gmer.exe; Driver: C:\Users\Ali\AppData\Local\Temp\kwtdrpow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x90A26202]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x910A5CB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x90A2881C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x90A28874]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x90A2898A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x90A28772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x90A288C4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x90A287C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x90A28938]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x90A26226]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x910A5D62]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x90A25FF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x90A2624A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x90A28D82]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x90A26CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x90A2884C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x90A2889C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x90A289B4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x90A2879E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x90A28904]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x90A287F4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x90A28962]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x910A5DFA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x90A26BA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x90A2626E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x90A26292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x90A2604A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x90A26186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x90A26162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x90A261AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x90A262B6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x910BB902]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 8304D569 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83072092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 214 83079824 4 Bytes [02, 62, A2, 90] {ADD AH, [EDX-0x5e]; NOP }
.text ntkrnlpa.exe!RtlSidHashLookup + 23C 8307984C 4 Bytes [B2, 5C, 0A, 91]
.text ntkrnlpa.exe!RtlSidHashLookup + 2F0 83079900 8 Bytes [1C, 88, A2, 90, 74, 88, A2, ...] {SBB AL, 0x88; MOV [0xa2887490], AL; NOP }
.text ntkrnlpa.exe!RtlSidHashLookup + 2FC 8307990C 4 Bytes [8A, 89, A2, 90]
.text ntkrnlpa.exe!RtlSidHashLookup + 318 83079928 4 Bytes [72, 87, A2, 90]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 832132CC 5 Bytes JMP 910B72BE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 8322D003 5 Bytes JMP 910B8D74 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 832775CA 4 Bytes CALL 90A2734B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 8327F6A4 4 Bytes CALL 90A27361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 832E52EC 7 Bytes JMP 910BB906 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text C:\windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8AF2F000, 0x3C849, 0xE8000020]
.dsrt C:\windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8AF74000, 0x3DC, 0x48000040]
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x97809000, 0x2D5526, 0xE8000020]
.text win32k.sys!EngMultiByteToUnicodeN + 7231 9A71987A 5 Bytes JMP 90A29342 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngIsSemaphoreOwned + 8A1B 9A7308AA 5 Bytes JMP 90A2946C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngEraseSurface + C12F 9A75172E 5 Bytes JMP 90A29E38 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 3322 9A764F4F 5 Bytes JMP 90A28F60 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 4027 9A765C54 5 Bytes JMP 90A29C04 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCTGetGammaTable + 177B 9A76B585 5 Bytes JMP 90A29352 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + 79DD 9A787AE0 5 Bytes JMP 90A28FD0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + 86C4 9A7887C7 5 Bytes JMP 90A28E84 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + 92B4 9A7893B7 5 Bytes JMP 90A291AC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateSemaphore + A5D0 9A7A41B4 5 Bytes JMP 90A29B90 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateSemaphore + C985 9A7A6569 5 Bytes JMP 90A28DB8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngBitBlt + 56E 9A7AFBAD 5 Bytes JMP 90A29BDA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngBitBlt + 5201 9A7B4840 5 Bytes JMP 90A2A040 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLpkInstalled + 6119 9A7C7A52 5 Bytes JMP 90A28E9C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLpkInstalled + 1AE86 9A7DC7BF 5 Bytes JMP 90A29C1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_bEnum + 9788 9A7EFCBC 5 Bytes JMP 90A29114 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 26C1 9A7F7D9A 5 Bytes JMP 90A29EF6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bPolyBezierTo + F8 9A80B815 5 Bytes JMP 90A290DA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngAcquireSemaphoreSharedNoWait + 1F5A 9A81B864 5 Bytes JMP 90A29F9E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_vGetBounds + EB5 9A84626F 5 Bytes JMP 90A29034 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCTGetCurrentGamma + 1C6C 9A84A27E 5 Bytes JMP 90A2906A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngSetPointerShape + C86 9A84CF34 5 Bytes JMP 90A29D80 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_cEnumStart + 6D0F 9A855C35 5 Bytes JMP 90A28F1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? C:\Users\Ali\AppData\Local\Temp\aswMBR.sys The system cannot find the file specified. !
? C:\Users\Ali\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
.text user32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes [E9, 88, 3D, 3C, 8A] {JMP 0xffffffff8a3c3d8d}
.text user32.dll!UnhookWinEvent 75E4D924 5 Bytes [E9, D3, 2A, 3C, 8A] {JMP 0xffffffff8a3c2ad8}
.text user32.dll!SetWindowsHookExW 75E5210A 5 Bytes [E9, F5, E6, 3B, 8A] {JMP 0xffffffff8a3be6fa}
.text user32.dll!SetWinEventHook 75E5507E 5 Bytes [E9, 75, B1, 3B, 8A] {JMP 0xffffffff8a3bb17a}
.text user32.dll!SetWindowsHookExA 75E76DFA 5 Bytes [E9, 01, 98, 39, 8A] {JMP 0xffffffff8a399806}
.text kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 003B0A08
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003B03FC
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 003B0804
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003B01F8
.text C:\Program Files\TOSHIBA\TECO\TecoService.exe[204] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 003B0600
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001503FC
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001501F8
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 002E0A08
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002E03FC
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 002E0804
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002E01F8
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[312] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 002E0600
.text C:\windows\system32\csrss.exe[416] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\wininit.exe[488] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000303FC
.text C:\windows\system32\wininit.exe[488] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000301F8
.text C:\windows\system32\wininit.exe[488] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\wininit.exe[488] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00050A08
.text C:\windows\system32\wininit.exe[488] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000503FC
.text C:\windows\system32\wininit.exe[488] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00050804
.text C:\windows\system32\wininit.exe[488] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000501F8
.text C:\windows\system32\wininit.exe[488] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00050600
.text C:\windows\system32\csrss.exe[500] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\services.exe[544] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\services.exe[544] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\services.exe[544] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\lsass.exe[560] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\lsass.exe[560] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\lsass.exe[560] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\lsm.exe[568] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000A03FC
.text C:\windows\system32\lsm.exe[568] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000A01F8
.text C:\windows\system32\lsm.exe[568] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\winlogon.exe[628] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000303FC
.text C:\windows\system32\winlogon.exe[628] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000301F8
.text C:\windows\system32\winlogon.exe[628] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\winlogon.exe[628] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 000C0A08
.text C:\windows\system32\winlogon.exe[628] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000C03FC
.text C:\windows\system32\winlogon.exe[628] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 000C0804
.text C:\windows\system32\winlogon.exe[628] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000C01F8
.text C:\windows\system32\winlogon.exe[628] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 000C0600
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00080A08
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000803FC
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00080804
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000801F8
.text C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe[672] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00080600
.text C:\windows\system32\svchost.exe[744] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[744] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[744] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[836] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[836] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[836] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\atiesrxx.exe[884] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\windows\system32\atiesrxx.exe[884] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\windows\system32\atiesrxx.exe[884] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\atiesrxx.exe[884] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\windows\system32\atiesrxx.exe[884] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\windows\system32\atiesrxx.exe[884] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\windows\system32\atiesrxx.exe[884] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\windows\system32\atiesrxx.exe[884] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\windows\system32\svchost.exe[916] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[916] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[916] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[920] KERNEL32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\svchost.exe[960] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\System32\svchost.exe[960] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\System32\svchost.exe[960] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\svchost.exe[960] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00200A08
.text C:\windows\System32\svchost.exe[960] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002003FC
.text C:\windows\System32\svchost.exe[960] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00200804
.text C:\windows\System32\svchost.exe[960] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002001F8
.text C:\windows\System32\svchost.exe[960] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00200600
.text C:\windows\System32\svchost.exe[1008] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\System32\svchost.exe[1008] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\System32\svchost.exe[1008] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\svchost.exe[1008] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00950A08
.text C:\windows\System32\svchost.exe[1008] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 009503FC
.text C:\windows\System32\svchost.exe[1008] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00950804
.text C:\windows\System32\svchost.exe[1008] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 009501F8
.text C:\windows\System32\svchost.exe[1008] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00950600
.text C:\windows\system32\svchost.exe[1040] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[1040] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[1040] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[1040] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 009F0A08
.text C:\windows\system32\svchost.exe[1040] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 009F03FC
.text C:\windows\system32\svchost.exe[1040] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 009F0804
.text C:\windows\system32\svchost.exe[1040] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 009F01F8
.text C:\windows\system32\svchost.exe[1040] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 009F0600
.text C:\windows\system32\wuauclt.exe[1048] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000703FC
.text C:\windows\system32\wuauclt.exe[1048] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000701F8
.text C:\windows\system32\wuauclt.exe[1048] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\wuauclt.exe[1048] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00090A08
.text C:\windows\system32\wuauclt.exe[1048] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000903FC
.text C:\windows\system32\wuauclt.exe[1048] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00090804
.text C:\windows\system32\wuauclt.exe[1048] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000901F8
.text C:\windows\system32\wuauclt.exe[1048] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00090600
.text C:\windows\system32\svchost.exe[1144] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000A03FC
.text C:\windows\system32\svchost.exe[1144] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000A01F8
.text C:\windows\system32\svchost.exe[1144] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[1144] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00410A08
.text C:\windows\system32\svchost.exe[1144] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 004103FC
.text C:\windows\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00410804
.text C:\windows\system32\svchost.exe[1144] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 004101F8
.text C:\windows\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00410600
.text C:\Windows\system32\TODDSrv.exe[1180] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Windows\system32\TODDSrv.exe[1180] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Windows\system32\TODDSrv.exe[1180] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Windows\system32\TODDSrv.exe[1180] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\Windows\system32\TODDSrv.exe[1180] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\Windows\system32\TODDSrv.exe[1180] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\Windows\system32\TODDSrv.exe[1180] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\Windows\system32\TODDSrv.exe[1180] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\windows\system32\svchost.exe[1288] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[1288] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[1288] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[1288] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00460A08
.text C:\windows\system32\svchost.exe[1288] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 004603FC
.text C:\windows\system32\svchost.exe[1288] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00460804
.text C:\windows\system32\svchost.exe[1288] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 004601F8
.text C:\windows\system32\svchost.exe[1288] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00460600
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] kernel32.dll!SetUnhandledExceptionFilter 75D63162 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\spoolsv.exe[1700] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\System32\spoolsv.exe[1700] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\System32\spoolsv.exe[1700] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\spoolsv.exe[1700] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00140A08
.text C:\windows\System32\spoolsv.exe[1700] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001403FC
.text C:\windows\System32\spoolsv.exe[1700] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00140804
.text C:\windows\System32\spoolsv.exe[1700] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001401F8
.text C:\windows\System32\spoolsv.exe[1700] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00140600
.text C:\windows\system32\svchost.exe[1732] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[1732] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[1732] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[1732] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00150A08
.text C:\windows\system32\svchost.exe[1732] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001503FC
.text C:\windows\system32\svchost.exe[1732] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00150804
.text C:\windows\system32\svchost.exe[1732] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001501F8
.text C:\windows\system32\svchost.exe[1732] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00150600
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00100A08
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001003FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00100804
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001001F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1828] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00100600
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00230A08
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002303FC
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00230804
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002301F8
.text C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1876] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00230600
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 01350A08
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 013503FC
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 01350804
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 013501F8
.text C:\Program Files\Flip Video\FlipShare\FlipShareService.exe[1908] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 01350600
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00920A08
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 009203FC
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00920804
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 009201F8
.text C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe[1992] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00920600
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00140A08
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001403FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00140804
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001401F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2044] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00140600
.text C:\windows\system32\SearchIndexer.exe[2100] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\SearchIndexer.exe[2100] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\SearchIndexer.exe[2100] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\SearchIndexer.exe[2100] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00100A08
.text C:\windows\system32\SearchIndexer.exe[2100] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001003FC
.text C:\windows\system32\SearchIndexer.exe[2100] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00100804
.text C:\windows\system32\SearchIndexer.exe[2100] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001001F8
.text C:\windows\system32\SearchIndexer.exe[2100] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00100600
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00090A08
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000903FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00090804
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000901F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2152] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00090600
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00330A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00330804
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00330600
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 003C6A90
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 003C6C90
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 0049000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WS2_32.dll!recv 755A47DF 5 Bytes JMP 0047000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WS2_32.dll!connect 755A48BE 5 Bytes JMP 0048000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 004C000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WS2_32.dll!send 755AC4C8 5 Bytes JMP 004A000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2180] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 004B000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2460] KERNEL32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00330A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00330804
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00330600
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 00436A90
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 00436C90
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 00A6000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WS2_32.dll!recv 755A47DF 5 Bytes JMP 0059000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WS2_32.dll!connect 755A48BE 5 Bytes JMP 005A000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 00A9000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WS2_32.dll!send 755AC4C8 5 Bytes JMP 00A7000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2504] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 00A8000A
.text C:\windows\system32\Dwm.exe[2544] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\Dwm.exe[2544] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\Dwm.exe[2544] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\Dwm.exe[2544] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00080A08
.text C:\windows\system32\Dwm.exe[2544] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000803FC
.text C:\windows\system32\Dwm.exe[2544] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00080804
.text C:\windows\system32\Dwm.exe[2544] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000801F8
.text C:\windows\system32\Dwm.exe[2544] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00080600
.text C:\windows\Explorer.EXE[2556] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\Explorer.EXE[2556] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\Explorer.EXE[2556] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\Explorer.EXE[2556] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00150A08
.text C:\windows\Explorer.EXE[2556] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001503FC
.text C:\windows\Explorer.EXE[2556] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00150804
.text C:\windows\Explorer.EXE[2556] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001501F8
.text C:\windows\Explorer.EXE[2556] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00150600
.text C:\windows\system32\taskhost.exe[2568] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\windows\system32\taskhost.exe[2568] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\windows\system32\taskhost.exe[2568] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\taskhost.exe[2568] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 000E0A08
.text C:\windows\system32\taskhost.exe[2568] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000E03FC
.text C:\windows\system32\taskhost.exe[2568] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 000E0804
.text C:\windows\system32\taskhost.exe[2568] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000E01F8
.text C:\windows\system32\taskhost.exe[2568] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 000E0600
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00130A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00130804
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00130600
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 00306A90
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 00306C90
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 0061000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WS2_32.dll!recv 755A47DF 5 Bytes JMP 005B000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WS2_32.dll!connect 755A48BE 5 Bytes JMP 0060000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 0075000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WS2_32.dll!send 755AC4C8 5 Bytes JMP 0062000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2700] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 0074000A
.text C:\Program Files\iPod\bin\iPodService.exe[2832] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\iPod\bin\iPodService.exe[2832] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\iPod\bin\iPodService.exe[2832] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[2832] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00100A08
.text C:\Program Files\iPod\bin\iPodService.exe[2832] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001003FC
.text C:\Program Files\iPod\bin\iPodService.exe[2832] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00100804
.text C:\Program Files\iPod\bin\iPodService.exe[2832] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001001F8
.text C:\Program Files\iPod\bin\iPodService.exe[2832] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00100600
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001A0A08
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001A03FC
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001A0804
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001A01F8
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2908] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001A0600
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2944] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00330A08
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003303FC
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00330804
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003301F8
.text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2976] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00330600
.text C:\windows\system32\wbem\unsecapp.exe[3016] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3020] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00180A08
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001803FC
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00180804
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001801F8
.text C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3056] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00180600
.text C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe[3104] KERNEL32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\AUDIODG.EXE[3120] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00230A08
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002303FC
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00230804
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002301F8
.text C:\Program Files\TOSHIBA\TECO\TEco.exe[3136] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00230600
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00270A08
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002703FC
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00270804
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002701F8
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[3160] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00270600
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 6C7583AA C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!CallNextHookEx 75E4CC8F 5 Bytes JMP 6C739D94 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 6C6F460B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00230600
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] ole32.dll!OleLoadFromStream 76025BF6 5 Bytes JMP 6C87059E C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] ole32.dll!CoCreateInstance 7607590C 5 Bytes JMP 6C748C75 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 009F6A90
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 009F6C90
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 004E000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WS2_32.dll!recv 755A47DF 5 Bytes JMP 004C000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WS2_32.dll!connect 755A48BE 5 Bytes JMP 004D000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 0051000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WS2_32.dll!send 755AC4C8 5 Bytes JMP 004F000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3180] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 0050000A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00210A08
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002103FC
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00210804
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002101F8
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3388] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00210600
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 000F0A08
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000F03FC
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 000F0804
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000F01F8
.text C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe[3436] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 000F0600
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 000F0A08
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000F03FC
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 000F0804
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000F01F8
.text C:\Program Files\iTunes\iTunesHelper.exe[3552] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 000F0600
.text C:\Program Files\Alwil Software\Avast5\AvastUI.exe[3560] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00310A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003103FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00310804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003101F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3600] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00310600
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3616] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 000F0A08
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000F03FC
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 000F0804
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000F01F8
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3636] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 000F0600
.text C:\Users\Ali\Desktop\gmer.exe[3676] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Users\Ali\Desktop\gmer.exe[3676] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Users\Ali\Desktop\gmer.exe[3676] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Users\Ali\Desktop\gmer.exe[3676] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00210A08
.text C:\Users\Ali\Desktop\gmer.exe[3676] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002103FC
.text C:\Users\Ali\Desktop\gmer.exe[3676] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00210804
.text C:\Users\Ali\Desktop\gmer.exe[3676] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002101F8
.text C:\Users\Ali\Desktop\gmer.exe[3676] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00210600
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 6C7583AA C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!CallNextHookEx 75E4CC8F 5 Bytes JMP 6C739D94 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 6C6F460B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00130600
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] ole32.dll!OleLoadFromStream 76025BF6 5 Bytes JMP 6C87059E C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] ole32.dll!CoCreateInstance 7607590C 5 Bytes JMP 6C748C75 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 00436A90
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 00436C90
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 0036000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WS2_32.dll!recv 755A47DF 5 Bytes JMP 0034000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WS2_32.dll!connect 755A48BE 5 Bytes JMP 0035000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 0039000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WS2_32.dll!send 755AC4C8 5 Bytes JMP 0037000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3704] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 0038000A
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[3740] KERNEL32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\atieclxx.exe[3936] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\windows\system32\atieclxx.exe[3936] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\windows\system32\atieclxx.exe[3936] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\atieclxx.exe[3936] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00200A08
.text C:\windows\system32\atieclxx.exe[3936] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002003FC
.text C:\windows\system32\atieclxx.exe[3936] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00200804
.text C:\windows\system32\atieclxx.exe[3936] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002001F8
.text C:\windows\system32\atieclxx.exe[3936] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00200600
.text C:\windows\system32\NOTEPAD.EXE[4132] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000A03FC
.text C:\windows\system32\NOTEPAD.EXE[4132] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000A01F8
.text C:\windows\system32\NOTEPAD.EXE[4132] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\NOTEPAD.EXE[4132] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00150A08
.text C:\windows\system32\NOTEPAD.EXE[4132] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001503FC
.text C:\windows\system32\NOTEPAD.EXE[4132] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00150804
.text C:\windows\system32\NOTEPAD.EXE[4132] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001501F8
.text C:\windows\system32\NOTEPAD.EXE[4132] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00150600
.text C:\windows\system32\wbem\wmiprvse.exe[4140] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\wbem\wmiprvse.exe[4140] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\wbem\wmiprvse.exe[4140] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\wbem\wmiprvse.exe[4140] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00100A08
.text C:\windows\system32\wbem\wmiprvse.exe[4140] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001003FC
.text C:\windows\system32\wbem\wmiprvse.exe[4140] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00100804
.text C:\windows\system32\wbem\wmiprvse.exe[4140] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001001F8
.text C:\windows\system32\wbem\wmiprvse.exe[4140] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00100600
.text C:\windows\system32\svchost.exe[4212] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[4212] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[4212] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[4212] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00270A08
.text C:\windows\system32\svchost.exe[4212] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002703FC
.text C:\windows\system32\svchost.exe[4212] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00270804
.text C:\windows\system32\svchost.exe[4212] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002701F8
.text C:\windows\system32\svchost.exe[4212] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00270600
.text C:\windows\system32\NOTEPAD.EXE[4260] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\NOTEPAD.EXE[4260] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\NOTEPAD.EXE[4260] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\NOTEPAD.EXE[4260] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00090A08
.text C:\windows\system32\NOTEPAD.EXE[4260] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000903FC
.text C:\windows\system32\NOTEPAD.EXE[4260] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00090804
.text C:\windows\system32\NOTEPAD.EXE[4260] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000901F8
.text C:\windows\system32\NOTEPAD.EXE[4260] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00090600
.text C:\windows\system32\svchost.exe[4268] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\svchost.exe[4268] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\svchost.exe[4268] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\svchost.exe[4268] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 008D0A08
.text C:\windows\system32\svchost.exe[4268] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 008D03FC
.text C:\windows\system32\svchost.exe[4268] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 008D0804
.text C:\windows\system32\svchost.exe[4268] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 008D01F8
.text C:\windows\system32\svchost.exe[4268] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 008D0600
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4388] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00180A08
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001803FC
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00180804
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001801F8
.text C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe[4448] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00180600
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 002F0A08
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002F03FC
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 002F0804
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002F01F8
.text C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4628] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 002F0600
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00200A08
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002003FC
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00200804
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002001F8
.text C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe[4732] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00200600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00100A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001003FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00100804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001001F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4828] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00100600
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 001F0A08
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001F03FC
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 001F0804
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001F01F8
.text C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe[4884] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 001F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 6C7583AA C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CallNextHookEx 75E4CC8F 5 Bytes JMP 6C739D94 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 6C6F460B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00230600
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ole32.dll!OleLoadFromStream 76025BF6 5 Bytes JMP 6C87059E C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ole32.dll!CoCreateInstance 7607590C 5 Bytes JMP 6C748C75 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 016A6A90
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 016A6C90
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 0192000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WS2_32.dll!recv 755A47DF 5 Bytes JMP 0047000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WS2_32.dll!connect 755A48BE 5 Bytes JMP 0048000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 01B9000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WS2_32.dll!send 755AC4C8 5 Bytes JMP 0193000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 01B8000A
.text C:\windows\System32\svchost.exe[4952] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\System32\svchost.exe[4952] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\System32\svchost.exe[4952] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\svchost.exe[4952] user32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00200A08
.text C:\windows\System32\svchost.exe[4952] user32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002003FC
.text C:\windows\System32\svchost.exe[4952] user32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00200804
.text C:\windows\System32\svchost.exe[4952] user32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002001F8
.text C:\windows\System32\svchost.exe[4952] user32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00200600
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00220A08
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002203FC
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00220804
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002201F8
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[5304] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00220600
.text C:\windows\system32\taskeng.exe[5436] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\system32\taskeng.exe[5436] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\system32\taskeng.exe[5436] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\system32\taskeng.exe[5436] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 000F0A08
.text C:\windows\system32\taskeng.exe[5436] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 000F03FC
.text C:\windows\system32\taskeng.exe[5436] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 000F0804
.text C:\windows\system32\taskeng.exe[5436] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 000F01F8
.text C:\windows\system32\taskeng.exe[5436] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 000F0600
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 003A0A08
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003A03FC
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 003A0804
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003A01F8
.text C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[5548] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 003A0600
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 001603FC
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 001601F8
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00380A08
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 003803FC
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00380804
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 003801F8
.text C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[5828] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00380600
.text C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe[5836] KERNEL32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\svchost.exe[6012] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000603FC
.text C:\windows\System32\svchost.exe[6012] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000601F8
.text C:\windows\System32\svchost.exe[6012] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\windows\System32\svchost.exe[6012] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 00200A08
.text C:\windows\System32\svchost.exe[6012] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 002003FC
.text C:\windows\System32\svchost.exe[6012] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 00200804
.text C:\windows\System32\svchost.exe[6012] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 002001F8
.text C:\windows\System32\svchost.exe[6012] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00200600
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] ntdll.dll!LdrUnloadDll 771ABEAF 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] ntdll.dll!LdrLoadDll 771AF5B5 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] kernel32.dll!GetBinaryTypeW + 70 75D77984 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!CreateDialogParamW 75E49BFF 5 Bytes JMP 6C69C580 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!EnableWindow 75E4A72E 5 Bytes JMP 6C69C4FB C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!GetAsyncKeyState 75E4C09A 5 Bytes JMP 6C65D6D1 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!UnhookWindowsHookEx 75E4CC7B 5 Bytes JMP 6C7583AA C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!CallNextHookEx 75E4CC8F 5 Bytes JMP 6C739D94 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!UnhookWinEvent 75E4D924 5 Bytes JMP 001303FC
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!CreateWindowExW 75E50E51 5 Bytes JMP 6C748187 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!SetWindowsHookExW 75E5210A 5 Bytes JMP 6C6F460B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!GetKeyState 75E54FDA 5 Bytes JMP 6C69D772 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!SetWinEventHook 75E5507E 5 Bytes JMP 001301F8
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!IsDialogMessageW 75E56F06 5 Bytes JMP 6C664264 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!CreateDialogParamA 75E63E79 5 Bytes JMP 6C870E41 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!IsDialogMessage 75E6407A 5 Bytes JMP 6C8706E2 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!CreateDialogIndirectParamA 75E69110 5 Bytes JMP 6C870E78 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!CreateDialogIndirectParamW 75E708AD 5 Bytes JMP 6C870EAF C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!DialogBoxIndirectParamW 75E74AA7 5 Bytes JMP 6C870240 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!EndDialog 75E7555C 5 Bytes JMP 6C665AC9 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!DialogBoxParamW 75E7564A 5 Bytes JMP 6C664B87 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!SetKeyboardState 75E76B52 5 Bytes JMP 6C870A47 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!SetWindowsHookExA 75E76DFA 5 Bytes JMP 00130600
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!SendInput 75E77055 5 Bytes JMP 6C87160C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!SetCursorPos 75E8C1D8 5 Bytes JMP 6C871664 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!DialogBoxParamA 75E8CF6A 5 Bytes JMP 6C8701DD C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!DialogBoxIndirectParamA 75E8D29C 5 Bytes JMP 6C8702A3 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!MessageBoxIndirectA 75E9E8C9 5 Bytes JMP 6C870172 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!MessageBoxIndirectW 75E9E9C3 5 Bytes JMP 6C870107 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!MessageBoxExA 75E9EA29 5 Bytes JMP 6C8700A5 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!MessageBoxExW 75E9EA4D 5 Bytes JMP 6C870043 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] USER32.dll!keybd_event 75E9EC9B 5 Bytes JMP 6C871997 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] SHELL32.dll!SHChangeNotification_Lock + 45BA 762BB440 4 Bytes [11, 36, CD, 6F] {ADC [ESI], ESI; INT 0x6f}
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] SHELL32.dll!SHChangeNotification_Lock + 45C2 762BB448 8 Bytes [5F, 35, CD, 6F, D0, 73, CC, ...] {POP EDI; XOR EAX, 0x73d06fcd; INT 3 ; OUTSD }
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] ole32.dll!OleLoadFromStream 76025BF6 5 Bytes JMP 6C87059E C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] ole32.dll!CoCreateInstance 7607590C 5 Bytes JMP 6C748C75 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WININET.dll!HttpAddRequestHeadersA 76F29ABA 5 Bytes JMP 016B6A90
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WININET.dll!HttpAddRequestHeadersW 76F30848 5 Bytes JMP 016B6C90
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WS2_32.dll!closesocket 755A3BED 5 Bytes JMP 0051000A
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WS2_32.dll!recv 755A47DF 5 Bytes JMP 004F000A
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WS2_32.dll!connect 755A48BE 5 Bytes JMP 0050000A
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WS2_32.dll!getaddrinfo 755A6737 5 Bytes JMP 0054000A
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WS2_32.dll!send 755AC4C8 5 Bytes JMP 0052000A
.text C:\Program Files\Internet Explorer\iexplore.exe[6108] WS2_32.dll!gethostbyname 755B7133 5 Bytes JMP 0053000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 868DE1ED
Device \Driver\atapi \Device\Ide\IdePort0 868DE1ED
Device \Driver\atapi \Device\Ide\IdePort1 868DE1ED
Device \Driver\atapi \Device\Ide\IdePort2 868DE1ED
Device \Driver\atapi \Device\Ide\IdePort3 868DE1ED
Device \Driver\atapi \Device\Ide\IdePort4 868DE1ED
Device \Driver\atapi \Device\Ide\IdePort5 868DE1ED
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 868DE1ED
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004d halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
---- Threads - GMER 1.0.15 ----
Thread System [4:212] 868E2E7A
Thread System [4:216] 868E5008
---- Files - GMER 1.0.15 ----
File C:\## aswSnx private storage 0 bytes
File C:\## aswSnx private storage\r34 0 bytes
File C:\## aswSnx private storage\snx_rhive 262144 bytes
File C:\## aswSnx private storage\snx_rhive.LOG1 37888 bytes
File C:\## aswSnx private storage\snx_rhive.LOG2 0 bytes
File C:\## aswSnx private storage\snx_rhive{254268a9-a4af-11e0-b935-001e33f784a2}.TM.blf 65536 bytes
File C:\## aswSnx private storage\snx_rhive{254268a9-a4af-11e0-b935-001e33f784a2}.TMContainer00000000000000000001.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\snx_rhive{254268a9-a4af-11e0-b935-001e33f784a2}.TMContainer00000000000000000002.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\webStorage 0 bytes
File C:\## aswSnx private storage\webStorage\attrib 0 bytes
File C:\## aswSnx private storage\webStorage\image 0 bytes
File C:\## aswSnx private storage\webStorage\image\windows 0 bytes
File C:\## aswSnx private storage\webStorage\image\windows\Prefetch 0 bytes
File C:\## aswSnx private storage\webStorage\image\windows\Prefetch\CONHOST.EXE-1F3E9D7E.pf 15754 bytes
File C:\## aswSnx private storage\webStorage\snx_fs.dat 474 bytes
---- EOF - GMER 1.0.15 ----