After stopping twice, I unchecked "Devices" and it ran. The results are too long to post here, is there a section you need? I will try to post some of it:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-07-17 16:30:23
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HDP725032GLA360 rev.GM3OA5BA
Running: 7ij8kq59.exe; Driver: C:\Users\Colleen\AppData\Local\Temp\uwdiafod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8F667202] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8F6697F0] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8F669848] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8F66995E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8F669746] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8F669898] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8F66979A] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8F66990C] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8F667226] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8F666FF0] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8F66724A] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8F669D56] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8F667CDA] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8F669820] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8F669870] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8F669988] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8F669772] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8F6698D8] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8F6697C8] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8F669936] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8F667BA0] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8F66726E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8F667292] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8F66704A] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8F667186] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8F667162] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8F6671AA] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8F6672B6] <-- ROOTKIT !!!
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 824EA890 4 Bytes [02, 72, 66, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1D1 824EA954 8 Bytes [F0, 97, 66, 8F, 48, 98, 66, ...]
.text ntkrnlpa.exe!KeSetEvent + 1DD 824EA960 4 Bytes [5E, 99, 66, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1F5 824EA978 4 Bytes [46, 97, 66, 8F]
.text ntkrnlpa.exe!KeSetEvent + 215 824EA998 2 Bytes [98, 98] {CWDE ; CWDE }
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82677E18 4 Bytes CALL 8F66834B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 8267BA8C 4 Bytes CALL 8F668361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? C:\Windows\System32\Drivers\1214969294.SYS Access is denied.
.text tdx.sys 8F784000 5 Bytes [00, 00, 00, 00, 00]
.text tdx.sys 8F784006 1 Byte [8B]
.text tdx.sys 8F784006 237 Bytes [8B, FF, 55, 8B, EC, 6A, 00, ...]
.text tdx.sys 8F7840F4 117 Bytes [75, 10, FF, 75, 14, 6A, 2B, ...]
.text tdx.sys 8F78416A 105 Bytes [04, 8D, 45, 18, 50, FF, 75, ...]
.text ...
? C:\Windows\system32\DRIVERS\tdx.sys suspicious PE modification
.text win32k.sys!EngCreateRectRgn + 4537 98ADFC80 5 Bytes JMP 8F66A440 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreatePalette + C20 98AF8EA9 5 Bytes JMP 8F66AE0C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 4A1 98AF9C95 5 Bytes JMP 8F66AF72 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 8C03 98B023F7 5 Bytes JMP 8F669D8C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 616 98B0334E 5 Bytes JMP 8F66ABD8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 3103 98B0EA94 5 Bytes JMP 8F66A316 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 456E 98B0FEFF 5 Bytes JMP 8F669F34 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 119C6 98B29A35 5 Bytes JMP 8F66A180 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMapFontFileFD + 11A1A 98B29A89 5 Bytes JMP 8F66A326 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 377F 98B50A8E 5 Bytes JMP 8F66AB64 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 60DE 98B533ED 5 Bytes JMP 8F669E58 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 4D3F 98B59D2E 5 Bytes JMP 8F669FA4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 2B42 98B641CC 5 Bytes JMP 8F66B014 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStrokePath + 5FF 98B670B4 5 Bytes JMP 8F669E70 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 81C 98B854E5 5 Bytes JMP 8F66AD54 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngNineGrid + 6EEA 98B8BBB3 5 Bytes JMP 8F66ABAE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCopyBits + B0F 98B8F32A 5 Bytes JMP 8F66ACA2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!STROBJ_vEnumStart + 4728 98B96C49 5 Bytes JMP 8F669EF0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + E80 98BB51BC 5 Bytes JMP 8F66A0AE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!CLIPOBJ_bEnum + 248 98BBAA3A 5 Bytes JMP 8F66A008 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 26D9 98BBE572 5 Bytes JMP 8F66AECA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + A0F 98BDCA97 5 Bytes JMP 8F66A03E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLineTo + D269 98BE92F1 5 Bytes JMP 8F66A0E8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\taskeng.exe[248] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskeng.exe[248] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskeng.exe[248] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\taskeng.exe[248] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\taskeng.exe[248] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\system32\taskeng.exe[248] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\system32\taskeng.exe[248] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\taskeng.exe[248] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\taskeng.exe[248] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\WUDFHost.exe[280] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\WUDFHost.exe[280] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\WUDFHost.exe[280] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\WUDFHost.exe[280] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\WUDFHost.exe[280] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\system32\WUDFHost.exe[280] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\system32\WUDFHost.exe[280] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\WUDFHost.exe[280] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\WUDFHost.exe[280] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00180600
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00181014
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00180804
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00180A08
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00180C0C
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00180E10
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001801F8
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00190600
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00190804
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00190A08
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001901F8
.text C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe[608] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001903FC
.text C:\Windows\system32\csrss.exe[648] KERNEL32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[692] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[692] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[692] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[692] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[692] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[692] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[692] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[692] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[692] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[704] KERNEL32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\services.exe[736] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[736] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[736] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[736] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[736] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Windows\system32\services.exe[736] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Windows\system32\services.exe[736] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\services.exe[736] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\services.exe[736] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\winlogon.exe[764] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[764] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[764] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000903FC
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00090600
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00091014
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00090804
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00090A08
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00090C0C
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00090E10
.text C:\Windows\system32\winlogon.exe[764] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000901F8
.text C:\Windows\system32\winlogon.exe[764] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000A0600
.text C:\Windows\system32\winlogon.exe[764] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000A0804
.text C:\Windows\system32\winlogon.exe[764] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000A0A08
.text C:\Windows\system32\winlogon.exe[764] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000A01F8
.text C:\Windows\system32\winlogon.exe[764] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\lsass.exe[780] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[780] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[780] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsass.exe[780] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\lsass.exe[780] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\system32\lsass.exe[780] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\system32\lsass.exe[780] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\lsass.exe[780] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\lsass.exe[780] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsm.exe[788] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[788] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[788] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsm.exe[788] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00180600
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00181014
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00180804
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00180A08
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00180C0C
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00180E10
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[840] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001801F8
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[952] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Windows\system32\svchost.exe[956] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[956] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[956] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[956] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[956] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 003F0600
.text C:\Windows\system32\svchost.exe[956] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 003F0804
.text C:\Windows\system32\svchost.exe[956] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 003F0A08
.text C:\Windows\system32\svchost.exe[956] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 003F01F8
.text C:\Windows\system32\svchost.exe[956] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 003F03FC
.text C:\Windows\system32\svchost.exe[1032] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1032] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1032] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Windows\system32\svchost.exe[1032] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Windows\system32\svchost.exe[1032] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\svchost.exe[1032] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1032] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Windows\System32\igfxpers.exe[1080] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Windows\System32\igfxpers.exe[1080] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Windows\System32\igfxpers.exe[1080] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\igfxpers.exe[1080] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Windows\System32\igfxpers.exe[1080] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Windows\System32\igfxpers.exe[1080] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Windows\System32\igfxpers.exe[1080] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Windows\System32\igfxpers.exe[1080] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 002803FC
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00280600
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00281014
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00280804
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00280A08
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00280C0C
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00280E10
.text C:\Windows\System32\igfxpers.exe[1080] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 002801F8
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001601F8
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001603FC
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00180600
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00181014
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00180804
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00180A08
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00180C0C
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00180E10
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1144] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001801F8
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000901F8
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000903FC
.text C:\Windows\System32\svchost.exe[1188] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000C03FC
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 000C0600
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 000C1014
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 000C0804
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 000C0A08
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 000C0C0C
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 000C0E10
.text C:\Windows\System32\svchost.exe[1188] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000C01F8
.text C:\Windows\System32\svchost.exe[1188] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00120600
.text C:\Windows\System32\svchost.exe[1188] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00120804
.text C:\Windows\System32\svchost.exe[1188] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00120A08
.text C:\Windows\System32\svchost.exe[1188] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001201F8
.text C:\Windows\System32\svchost.exe[1188] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001203FC
.text C:\Windows\System32\svchost.exe[1212] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1212] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1212] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00CD0600
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00CD0804
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00CD0A08
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 00CD01F8
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 00CD03FC
.text C:\Windows\system32\SearchIndexer.exe[1220] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchIndexer.exe[1220] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchIndexer.exe[1220] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\SearchIndexer.exe[1220] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\SearchIndexer.exe[1220] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\system32\SearchIndexer.exe[1220] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\system32\SearchIndexer.exe[1220] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\SearchIndexer.exe[1220] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\SearchIndexer.exe[1220] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[1224] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1224] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1224] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000D0600
.text C:\Windows\system32\svchost.exe[1224] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000D0804
.text C:\Windows\system32\svchost.exe[1224] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000D0A08
.text C:\Windows\system32\svchost.exe[1224] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000D01F8
.text C:\Windows\system32\svchost.exe[1224] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000D03FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00090600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00090804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00090A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000901F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1272] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000903FC
.text C:\Windows\system32\AUDIODG.EXE[1364] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1436] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1436] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1436] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1436] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1436] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00470600
.text C:\Windows\system32\svchost.exe[1436] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00470804
.text C:\Windows\system32\svchost.exe[1436] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00470A08
.text C:\Windows\system32\svchost.exe[1436] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 004701F8
.text C:\Windows\system32\svchost.exe[1436] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 004703FC
.text C:\Windows\System32\svchost.exe[1444] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1444] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1444] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1444] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1468] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1468] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000801F8
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001401F8
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001403FC
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00160600
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00160804
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00160A08
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001601F8
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001603FC
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1496] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Windows\system32\svchost.exe[1612] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1612] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1612] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1612] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1612] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000F0600
.text C:\Windows\system32\svchost.exe[1612] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000F0804
.text C:\Windows\system32\svchost.exe[1612] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000F0A08
.text C:\Windows\system32\svchost.exe[1612] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000F01F8
.text C:\Windows\system32\svchost.exe[1612] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000F03FC
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1680] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1680] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000F0600
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000F0804
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000F0A08
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000F01F8
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000F03FC
.text C:\Windows\RtHDVCpl.exe[1732] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Windows\RtHDVCpl.exe[1732] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Windows\RtHDVCpl.exe[1732] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Windows\RtHDVCpl.exe[1732] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Windows\RtHDVCpl.exe[1732] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Windows\RtHDVCpl.exe[1732] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Windows\RtHDVCpl.exe[1732] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Windows\RtHDVCpl.exe[1732] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Windows\RtHDVCpl.exe[1732] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001401F8
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001403FC
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001603FC
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00160600
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00161014
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00160804
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00160A08
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00160C0C
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00160E10
.text C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe[1800] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001601F8
.text C:\Windows\System32\spoolsv.exe[1808] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\spoolsv.exe[1808] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\spoolsv.exe[1808] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\spoolsv.exe[1808] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\spoolsv.exe[1808] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00160600
.text C:\Windows\System32\spoolsv.exe[1808] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00160804
.text C:\Windows\System32\spoolsv.exe[1808] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00160A08
.text C:\Windows\System32\spoolsv.exe[1808] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001601F8
.text C:\Windows\System32\spoolsv.exe[1808] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001603FC
.text C:\Windows\system32\svchost.exe[1836] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1836] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1836] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000B0600
.text C:\Windows\system32\svchost.exe[1836] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000B0804
.text C:\Windows\system32\svchost.exe[1836] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000B0A08
.text C:\Windows\system32\svchost.exe[1836] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000B01F8
.text C:\Windows\system32\svchost.exe[1836] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000B03FC
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\WindowsMobile\wmdSync.exe[1872] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\igfxsrvc.exe[1944] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\igfxsrvc.exe[1944] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Windows\system32\igfxsrvc.exe[1944] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\igfxsrvc.exe[1944] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Windows\system32\igfxsrvc.exe[1944] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Windows\system32\igfxsrvc.exe[1944] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Windows\system32\igfxsrvc.exe[1944] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Windows\system32\igfxsrvc.exe[1944] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 002803FC
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00280600
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00281014
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00280804
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00280A08
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00280C0C
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00280E10
.text C:\Windows\system32\igfxsrvc.exe[1944] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 002801F8
.text C:\Windows\system32\AERTSrv.exe[2024] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\AERTSrv.exe[2024] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Windows\system32\AERTSrv.exe[2024] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Windows\system32\AERTSrv.exe[2024] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Windows\System32\igfxtray.exe[2072] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Windows\System32\igfxtray.exe[2072] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Windows\System32\igfxtray.exe[2072] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\igfxtray.exe[2072] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00280600
.text C:\Windows\System32\igfxtray.exe[2072] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00280804
.text C:\Windows\System32\igfxtray.exe[2072] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00280A08
.text C:\Windows\System32\igfxtray.exe[2072] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 002801F8
.text C:\Windows\System32\igfxtray.exe[2072] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 002803FC
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 002903FC
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00290600
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00291014
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00290804
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00290A08
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00290C0C
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00290E10
.text C:\Windows\System32\igfxtray.exe[2072] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 002901F8
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001401F8
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001403FC
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001603FC
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00160600
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00161014
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00160804
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00160A08
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00160C0C
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00160E10
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001601F8
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Windows\system32\DRIVERS\xaudio.exe[2084] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001903FC
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00190600
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00191014
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00190804
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00190A08
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00190C0C
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00190E10
.text C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe[2104] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001901F8
.text C:\Windows\System32\hkcmd.exe[2152] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Windows\System32\hkcmd.exe[2152] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Windows\System32\hkcmd.exe[2152] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\hkcmd.exe[2152] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Windows\System32\hkcmd.exe[2152] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Windows\System32\hkcmd.exe[2152] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Windows\System32\hkcmd.exe[2152] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Windows\System32\hkcmd.exe[2152] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001903FC
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00190600
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00191014
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00190804
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00190A08
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00190C0C
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00190E10
.text C:\Windows\System32\hkcmd.exe[2152] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001901F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00180600
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00181014
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00180804
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00180A08
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00180C0C
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00180E10
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2340] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001801F8
.text C:\Windows\ehome\ehmsas.exe[2348] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000401F8
.text C:\Windows\ehome\ehmsas.exe[2348] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000403FC
.text C:\Windows\ehome\ehmsas.exe[2348] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000603FC
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00060600
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00061014
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00060804
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00060A08
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00060C0C
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00060E10
.text C:\Windows\ehome\ehmsas.exe[2348] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000601F8
.text C:\Windows\ehome\ehmsas.exe[2348] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00070600
.text C:\Windows\ehome\ehmsas.exe[2348] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00070804
.text C:\Windows\ehome\ehmsas.exe[2348] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00070A08
.text C:\Windows\ehome\ehmsas.exe[2348] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000701F8
.text C:\Windows\ehome\ehmsas.exe[2348] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000703FC
.text F:\7ij8kq59.exe[2428] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text F:\7ij8kq59.exe[2428] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text F:\7ij8kq59.exe[2428] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001A03FC
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 001A0600
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 001A1014
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 001A0804
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 001A0A08
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 001A0C0C
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 001A0E10
.text F:\7ij8kq59.exe[2428] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001A01F8
.text F:\7ij8kq59.exe[2428] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 001B0600
.text F:\7ij8kq59.exe[2428] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 001B0804
.text F:\7ij8kq59.exe[2428] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 001B0A08
.text F:\7ij8kq59.exe[2428] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001B01F8
.text F:\7ij8kq59.exe[2428] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001B03FC
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001601F8
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001603FC
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Program Files\Google\Update\GoogleUpdate.exe[2548] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2636] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\ehome\ehtray.exe[2728] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\ehome\ehtray.exe[2728] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\ehome\ehtray.exe[2728] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000B03FC
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 000B0600
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 000B1014
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 000B0804
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 000B0A08
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 000B0C0C
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 000B0E10
.text C:\Windows\ehome\ehtray.exe[2728] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000B01F8
.text C:\Windows\ehome\ehtray.exe[2728] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000C0600
.text C:\Windows\ehome\ehtray.exe[2728] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000C0804
.text C:\Windows\ehome\ehtray.exe[2728] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000C0A08
.text C:\Windows\ehome\ehtray.exe[2728] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000C01F8
.text C:\Windows\ehome\ehtray.exe[2728] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000C03FC
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00180600
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00180804
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00180A08
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001801F8
.text C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe[2732] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001803FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001501F8
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001503FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00170600
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00170804
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00170A08
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001701F8
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001703FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001803FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00180600
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00181014
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00180804
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00180A08
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00180C0C
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00180E10
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2736] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001801F8
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000401F8
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000403FC
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000603FC
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00060600
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00061014
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00060804
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00060A08
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00060C0C
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00060E10
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000601F8
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00070600
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00070804
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00070A08
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Internet Explorer\ieuser.exe[2832] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000603FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00060600
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00061014
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00060804
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00060A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00060C0C
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00060E10
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000601F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00070600
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00070804
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00070A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!DialogBoxParamW 76F710B0 5 Bytes JMP 6C41C00F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!DialogBoxIndirectParamW 76F72EF5 5 Bytes JMP 6C55BC22 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!DialogBoxParamA 76F88152 5 Bytes JMP 6C55BBE7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!DialogBoxIndirectParamA 76F8847D 5 Bytes JMP 6C55BC5D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!MessageBoxIndirectA 76F9D4D9 5 Bytes JMP 6C55BBA3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!MessageBoxIndirectW 76F9D5D3 5 Bytes JMP 6C55BB5F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!MessageBoxExA 76F9D639 5 Bytes JMP 6C55BB25 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] USER32.dll!MessageBoxExW 76F9D65D 5 Bytes JMP 6C55BAEB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] SHELL32.dll!SHRestricted + D95 760189A8 4 Bytes [99, 0B, 1C, 6C] {CDQ ; OR EBX, [ESP+EBP*2]}
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] SHELL32.dll!SHRestricted + D9D 760189B0 8 Bytes [A7, 0A, 1C, 6C, A4, 32, 1B, ...] {CMPSD ; OR BL, [ESP+EBP*2]; MOVSB ; XOR BL, [EBX]; INSB }
.text C:\Program Files\Internet Explorer\iexplore.exe[2844] ole32.dll!OleLoadFromStream 75E01E80 5 Bytes JMP 6C55BE1F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 001401F8
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 001403FC
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00160600
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00160804
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00160A08
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 001601F8
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 001603FC
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 001703FC
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00170600
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00171014
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00170804
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00170A08
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00170C0C
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00170E10
.text C:\Program Files\My Book\WD Backup\uBBMonitor.exe[2884] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 001701F8
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000603FC
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00460600
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00460804
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00460A08
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 004601F8
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 004603FC
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 004503FC
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00450600
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00451014
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00450804
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00450A08
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00450C0C
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00450E10
.text C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe[3208] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 004501F8
.text C:\Windows\system32\svchost.exe[3264] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[3264] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[3264] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[3264] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[3352] KERNEL32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\wuauclt.exe[3472] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000601F8
.text C:\Windows\system32\wuauclt.exe[3472] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000603FC
.text C:\Windows\system32\wuauclt.exe[3472] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\wuauclt.exe[3472] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00070600
.text C:\Windows\system32\wuauclt.exe[3472] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00070804
.text C:\Windows\system32\wuauclt.exe[3472] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00070A08
.text C:\Windows\system32\wuauclt.exe[3472] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000701F8
.text C:\Windows\system32\wuauclt.exe[3472] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000703FC
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\wuauclt.exe[3472] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\wermgr.exe[3616] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000901F8
.text C:\Windows\system32\wermgr.exe[3616] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000903FC
.text C:\Windows\system32\wermgr.exe[3616] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000C03FC
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 000C0600
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 000C1014
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 000C0804
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 000C0A08
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 000C0C0C
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 000C0E10
.text C:\Windows\system32\wermgr.exe[3616] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000C01F8
.text C:\Windows\system32\wermgr.exe[3616] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000D0600
.text C:\Windows\system32\wermgr.exe[3616] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000D0804
.text C:\Windows\system32\wermgr.exe[3616] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000D0A08
.text C:\Windows\system32\wermgr.exe[3616] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000D01F8
.text C:\Windows\system32\wermgr.exe[3616] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000D03FC
.text C:\Windows\system32\taskeng.exe[3764] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskeng.exe[3764] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskeng.exe[3764] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\taskeng.exe[3764] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\taskeng.exe[3764] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\system32\taskeng.exe[3764] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\system32\taskeng.exe[3764] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\taskeng.exe[3764] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\taskeng.exe[3764] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\Dwm.exe[3824] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000901F8
.text C:\Windows\system32\Dwm.exe[3824] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000903FC
.text C:\Windows\system32\Dwm.exe[3824] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\Dwm.exe[3824] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\Dwm.exe[3824] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000C0600
.text C:\Windows\system32\Dwm.exe[3824] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000C0804
.text C:\Windows\system32\Dwm.exe[3824] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000C0A08
.text C:\Windows\system32\Dwm.exe[3824] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000C01F8
.text C:\Windows\system32\Dwm.exe[3824] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000C03FC
.text C:\Windows\Explorer.EXE[3876] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\Explorer.EXE[3876] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\Explorer.EXE[3876] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\Explorer.EXE[3876] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\Explorer.EXE[3876] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\Explorer.EXE[3876] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\Explorer.EXE[3876] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\Explorer.EXE[3876] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\Explorer.EXE[3876] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[4052] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[4052] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[4052] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[4052] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[4052] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 000E0600
.text C:\Windows\system32\svchost.exe[4052] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 000E0804
.text C:\Windows\system32\svchost.exe[4052] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 000E0A08
.text C:\Windows\system32\svchost.exe[4052] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000E01F8
.text C:\Windows\system32\svchost.exe[4052] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000E03FC
.text C:\Windows\System32\wpcumi.exe[4092] ntdll.dll!LdrLoadDll 775A93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\wpcumi.exe[4092] ntdll.dll!LdrUnloadDll 775BB740 5 Bytes JMP 000503FC
.text C:\Windows\System32\wpcumi.exe[4092] kernel32.dll!GetBinaryTypeW + 70 76C32467 1 Byte [62]
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!CreateServiceW 77109EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!DeleteService 7710A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!SetServiceObjectSecurity 77146CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!ChangeServiceConfigA 77146DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!ChangeServiceConfigW 77146F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!ChangeServiceConfig2A 77147099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!ChangeServiceConfig2W 771471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\wpcumi.exe[4092] ADVAPI32.dll!CreateServiceA 771472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\wpcumi.exe[4092] USER32.dll!SetWindowsHookExA 76F46322 5 Bytes JMP 00080600
.text C:\Windows\System32\wpcumi.exe[4092] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 00080804
.text C:\Windows\System32\wpcumi.exe[4092] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 00080A08
.text C:\Windows\System32\wpcumi.exe[4092] USER32.dll!SetWinEventHook 76F49F3A 5 Bytes JMP 000801F8
.text C:\Windows\System32\wpcumi.exe[4092] USER32.dll!UnhookWinEvent 76F4C06F 5 Bytes JMP 000803FC