GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-06 00:10:23
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PC3O
Running: gmer.exe; Driver: C:\Users\SEBAST~1\AppData\Local\Temp\kglyauoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x90629374]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x90EA92B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x9062B996]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x9062B9EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x9062BB04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x9062B8EC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x9062BA3E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x9062B940]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x9062BAB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x90629398]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x90EA9368]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x90629162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x906293BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x9062BEFC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x90629E54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x9062B9C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x9062BA16]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x9062BB2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x9062B918]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x9062BA7E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x9062B96E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x9062BADC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x90EA9400]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x90629D1A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x906293E0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x90629404]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x906291BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x906292F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x906292D4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x9062931C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x90629428]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x90EBE9A6]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 84092349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 840CBD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 840D2D80 4 Bytes [74, 93, 62, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 840D2DA8 4 Bytes [B8, 92, EA, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 840D2E5C 8 Bytes [96, B9, 62, 90, EE, B9, 62, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 840D2E68 4 Bytes [04, BB, 62, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 840D2E84 4 Bytes [EC, B8, 62, 90]
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91A2A000, 0x341EAE, 0xE8000020]
? C:\Users\SEBAST~1\AppData\Local\Temp\mbr.sys 系统找不到指定的文件。 !
.text ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes [E9, 19, 3B, 62, 88] {JMP 0xffffffff88623b1e}
.text ntdll.dll!LdrLoadDll 77B422B8 5 Bytes [E9, 3B, DF, 61, 88] {JMP 0xffffffff8861df40}
.text user32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes [E9, 0A, 5C, 7A, 88] {JMP 0xffffffff887a5c0f}
.text user32.dll!UnhookWinEvent 77C4B750 5 Bytes [E9, A7, 4C, 7A, 88] {JMP 0xffffffff887a4cac}
.text user32.dll!SetWindowsHookExW 77C4E30C 5 Bytes [E9, F3, 24, 7A, 88] {JMP 0xffffffff887a24f8}
.text user32.dll!SetWinEventHook 77C524DC 5 Bytes [E9, 17, DD, 79, 88] {JMP 0xffffffff8879dd1c}
.text user32.dll!SetWindowsHookExA 77C76D0C 5 Bytes [E9, EF, 98, 77, 88] {JMP 0xffffffff887798f4}
.text kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[368] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[368] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[368] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[368] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00900A08
.text C:\Windows\system32\svchost.exe[368] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 009003FC
.text C:\Windows\system32\svchost.exe[368] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00900804
.text C:\Windows\system32\svchost.exe[368] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 009001F8
.text C:\Windows\system32\svchost.exe[368] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00900600
.text C:\Windows\system32\csrss.exe[440] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[520] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[520] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[520] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[520] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[520] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000603FC
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00060600
.text C:\Windows\system32\csrss.exe[528] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001003FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00100804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001001F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[568] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\services.exe[576] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000A03FC
.text C:\Windows\system32\services.exe[576] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000A01F8
.text C:\Windows\system32\services.exe[576] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[608] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[608] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[608] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00050A08
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000503FC
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00050804
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000501F8
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00050600
.text C:\Windows\system32\lsass.exe[620] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[620] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[620] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\aestsrv.exe[624] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\aestsrv.exe[624] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\aestsrv.exe[624] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\lsm.exe[628] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsm.exe[628] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsm.exe[628] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[848] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[848] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[848] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[896] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atiesrxx.exe[896] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atiesrxx.exe[896] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[896] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atiesrxx.exe[896] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atiesrxx.exe[896] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\atiesrxx.exe[896] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atiesrxx.exe[896] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000703FC
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000701F8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001E0A08
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001E03FC
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001E0804
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001E01F8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[936] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001E0600
.text C:\Windows\System32\svchost.exe[968] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[968] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[968] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[968] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00200A08
.text C:\Windows\System32\svchost.exe[968] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 002003FC
.text C:\Windows\System32\svchost.exe[968] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00200804
.text C:\Windows\System32\svchost.exe[968] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 002001F8
.text C:\Windows\System32\svchost.exe[968] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00200600
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[1004] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00A60A08
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 00A603FC
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00A60804
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 00A601F8
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00A60600
.text C:\Windows\system32\svchost.exe[1052] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1052] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1052] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1052] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 01140A08
.text C:\Windows\system32\svchost.exe[1052] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 011403FC
.text C:\Windows\system32\svchost.exe[1052] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 01140804
.text C:\Windows\system32\svchost.exe[1052] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 011401F8
.text C:\Windows\system32\svchost.exe[1052] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 01140600
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00300A08
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 003003FC
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00300804
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 003001F8
.text C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_be0aa592be2f1430\STacSV.exe[1092] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00300600
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 002F0A08
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 002F03FC
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 002F0804
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 002F01F8
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[1116] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 002F0600
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtCreateFile + 6 77B255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtCreateFile + B 77B255D3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtMapViewOfSection + 6 77B25C2E 1 Byte [28]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtMapViewOfSection + 6 77B25C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtMapViewOfSection + B 77B25C33 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenFile + 6 77B25CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenFile + B 77B25CE3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcess + 6 77B25D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcess + B 77B25D93 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessToken + 6 77B25D9E 4 Bytes CALL 76B264A4 C:\Windows\system32\ole32.dll (用于 Windows 的 Microsoft OLE/Microsoft Corporation)
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessToken + B 77B25DA3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessTokenEx + 6 77B25DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessTokenEx + B 77B25DB3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThread + 6 77B25E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThread + B 77B25E13 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadToken + 6 77B25E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadToken + B 77B25E23 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadTokenEx + 6 77B25E2E 4 Bytes CALL 76B26535 C:\Windows\system32\ole32.dll (用于 Windows 的 Microsoft OLE/Microsoft Corporation)
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadTokenEx + B 77B25E33 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryAttributesFile + 6 77B25F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryAttributesFile + B 77B25F43 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryFullAttributesFile + 6 77B25FEE 4 Bytes CALL 76B266F3 C:\Windows\system32\ole32.dll (用于 Windows 的 Microsoft OLE/Microsoft Corporation)
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryFullAttributesFile + B 77B25FF3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationFile + 6 77B2663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationFile + B 77B26643 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationThread + 6 77B2669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationThread + B 77B266A3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtUnmapViewOfSection + 6 77B269BE 1 Byte [68]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtUnmapViewOfSection + 6 77B269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtUnmapViewOfSection + B 77B269C3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000803FC
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000801F8
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00120A08
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001203FC
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00120804
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001201F8
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[1224] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00120600
.text C:\Windows\system32\svchost.exe[1232] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1232] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1232] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1276] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1276] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1276] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 009A0A08
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 009A03FC
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 009A0804
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 009A01F8
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 009A0600
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000F0A08
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000F03FC
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000F0804
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000F01F8
.text C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe[1324] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\atieclxx.exe[1332] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atieclxx.exe[1332] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atieclxx.exe[1332] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\atieclxx.exe[1332] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atieclxx.exe[1332] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atieclxx.exe[1332] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\atieclxx.exe[1332] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atieclxx.exe[1332] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\Hpservice.exe[1356] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\Hpservice.exe[1356] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Hpservice.exe[1356] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\Hpservice.exe[1356] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00090A08
.text C:\Windows\system32\Hpservice.exe[1356] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000903FC
.text C:\Windows\system32\Hpservice.exe[1356] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00090804
.text C:\Windows\system32\Hpservice.exe[1356] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000901F8
.text C:\Windows\system32\Hpservice.exe[1356] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00090600
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[1408] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00340A08
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 003403FC
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00340804
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 003401F8
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00340600
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 003F0A08
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 003F03FC
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 003F0804
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 003F01F8
.text C:\Users\Sebastien\Desktop\gmer.exe[1468] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 003F0600
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1612] kernel32.dll!SetUnhandledExceptionFilter 761CF4FB 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1612] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1644] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[2040] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\spoolsv.exe[2040] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\spoolsv.exe[2040] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[2040] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000A0A08
.text C:\Windows\System32\spoolsv.exe[2040] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000A03FC
.text C:\Windows\System32\spoolsv.exe[2040] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000A0804
.text C:\Windows\System32\spoolsv.exe[2040] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000A01F8
.text C:\Windows\System32\spoolsv.exe[2040] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000A0600
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001B0A08
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001B03FC
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001B0804
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001B01F8
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2080] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001B0600
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00200A08
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 002003FC
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00200804
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 002001F8
.text C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe[2120] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00200600
.text C:\Windows\system32\svchost.exe[2176] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2176] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2176] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001003FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00100804
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001001F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2236] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00100600
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001701F8
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00300A08
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 003003FC
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00300804
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 003001F8
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2316] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00300600
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000A03FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000A01F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000D0A08
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000D03FC
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000D0804
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000D01F8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2348] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000D0600
.text C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe[2372] KERNEL32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000A03FC
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000A01F8
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00250A08
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 002503FC
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00250804
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 002501F8
.text C:\Windows\system32\wbem\wmiprvse.exe[2804] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00250600
.text C:\Windows\system32\svchost.exe[2888] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2888] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2888] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2888] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00160A08
.text C:\Windows\system32\svchost.exe[2888] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001603FC
.text C:\Windows\system32\svchost.exe[2888] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00160804
.text C:\Windows\system32\svchost.exe[2888] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001601F8
.text C:\Windows\system32\svchost.exe[2888] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00160600
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000F0A08
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000F03FC
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000F0804
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000F01F8
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3108] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\Dwm.exe[3136] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[3136] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[3136] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[3136] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\Dwm.exe[3136] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\Dwm.exe[3136] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\Dwm.exe[3136] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\Dwm.exe[3136] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000F0600
.text C:\Windows\Explorer.EXE[3176] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000A03FC
.text C:\Windows\Explorer.EXE[3176] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000A01F8
.text C:\Windows\Explorer.EXE[3176] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[3176] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000E0A08
.text C:\Windows\Explorer.EXE[3176] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000E03FC
.text C:\Windows\Explorer.EXE[3176] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000E0804
.text C:\Windows\Explorer.EXE[3176] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000E01F8
.text C:\Windows\Explorer.EXE[3176] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000E0600
.text C:\Windows\system32\taskhost.exe[3228] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[3228] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[3228] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[3228] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00220A08
.text C:\Windows\system32\taskhost.exe[3228] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 002203FC
.text C:\Windows\system32\taskhost.exe[3228] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00220804
.text C:\Windows\system32\taskhost.exe[3228] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 002201F8
.text C:\Windows\system32\taskhost.exe[3228] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00220600
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3404] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe[3412] KERNEL32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\igfxpers.exe[3460] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Windows\System32\igfxpers.exe[3460] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Windows\System32\igfxpers.exe[3460] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Windows\System32\igfxpers.exe[3460] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00310A08
.text C:\Windows\System32\igfxpers.exe[3460] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 003103FC
.text C:\Windows\System32\igfxpers.exe[3460] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00310804
.text C:\Windows\System32\igfxpers.exe[3460] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 003101F8
.text C:\Windows\System32\igfxpers.exe[3460] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00310600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3480] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3500] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 00210600
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 000603FC
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 000601F8
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 000F0A08
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 000F03FC
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 000F0804
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 000F01F8
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3624] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 000F0600
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] ntdll.dll!LdrUnloadDll 77B3C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] ntdll.dll!LdrLoadDll 77B422B8 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] kernel32.dll!GetBinaryTypeW + 70 761E69F4 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] USER32.dll!UnhookWindowsHookEx 77C4ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] USER32.dll!UnhookWinEvent 77C4B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] USER32.dll!SetWindowsHookExW 77C4E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] USER32.dll!SetWinEventHook 77C524DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3884] USER32.dll!SetWindowsHookExA 77C76D0C 5 Bytes JMP 001F0600
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtCreateFile + 6 77B255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtCreateFile + B 77B255D3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtMapViewOfSection + 6 77B25C2E 1 Byte [28]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtMapViewOfSection + 6 77B25C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtMapViewOfSection + B 77B25C33 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtOpenFile + 6 77B25CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtOpenFile + B 77B25CE3 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtOpenProcess + 6 77B25D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtOpenProcess + B 77B25D93 1 Byte [E2]
.text C:\Users\Sebastien\AppData\Local\Google\Chrome\Application\chrome.exe[3988] ntdll.dll!NtOpenProcessToken + 6 77B25D9E 4 Bytes CALL 76B264A4
Attached File(s)
-
Attach.txt (4.56K)
Number of downloads: 0 -
DDS.txt (18.34K)
Number of downloads: 0

Help
This topic is locked


Back to top













