OK.
[CODE]
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-14 13:55:48
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-2 ST2000DL003-9VT166 rev.CC3C 1863,02GB
Running: zio8i03t.exe; Driver: C:\Users\HANS-D~1\AppData\Local\Temp\awldipow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800033f3000 45 bytes [00, 00, 13, 02, 48, 6F, 6F, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 574 fffff800033f302e 8 bytes [5C, 00, 4D, 00, 41, 00, 43, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\winlogon.exe[540] C:\Windows\system32\USER32.dll!PeekMessageA 0000000076f73a18 14 bytes [68, C0, 38, E2, FC, C7, 44, ...]
.text C:\Windows\system32\winlogon.exe[540] C:\Windows\system32\USER32.dll!GetMessageA 0000000076f76110 14 bytes [68, C0, 37, E2, FC, C7, 44, ...]
.text C:\Windows\system32\winlogon.exe[540] C:\Windows\system32\USER32.dll!IsDialogMessageW 0000000076f766c0 14 bytes [68, 80, 37, E2, FC, C7, 44, ...]
.text C:\Windows\system32\winlogon.exe[540] C:\Windows\system32\USER32.dll!PeekMessageW 0000000076f78fd0 14 bytes [68, 60, 39, E2, FC, C7, 44, ...]
.text C:\Windows\system32\winlogon.exe[540] C:\Windows\system32\USER32.dll!GetMessageW 0000000076f79e74 14 bytes [68, 40, 38, E2, FC, C7, 44, ...]
.text C:\Windows\system32\winlogon.exe[540] C:\Windows\system32\USER32.dll!IsDialogMessage 0000000076fb3268 14 bytes [68, 40, 37, E2, FC, C7, 44, ...]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe[2208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2252] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe[3140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[3280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\PDF Architect\HelperService.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\PDF Architect\ConversionService.exe[3568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[3624] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[3624] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe[3716] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[3816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe[3532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe[4424] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe[4424] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe[4424] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe[4424] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe[4424] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe[4424] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe[4656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe[4792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe[4816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5060] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Users\Hans-Dieter\AppData\Local\Akamai\netsession_win.exe[5104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe[4540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe[5292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\kernel32.dll!CreateThread + 28 00000000753c3491 4 bytes {CALL 0xffffffff8b3bb300}
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[5316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Avanquest\PDF Experte 8 Professional\vspdfprsrv.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5408] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe[5528] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[5668] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5696] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Users\Hans-Dieter\AppData\Local\Apps\2.0\P2EZC2G6.D1J\ZTJ8VNON.6C0\frit..tion_8488884cfbcefd60_0002.0003_f406d43803d5433d\fritzbox-usb-fernanschluss.exe[6940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe[6176] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe[3164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe[5360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[1444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[7728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075b978e2 6 bytes [68, 00, 37, A8, 74, C3]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075b97bd3 6 bytes [68, 60, 36, A8, 74, C3]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075ba05ba 6 bytes [68, 50, 38, A8, 74, C3]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075ba5f74 6 bytes [68, A0, 37, A8, 74, C3]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075bb50ed 6 bytes [68, 60, 35, A8, 74, C3]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075bbc701 6 bytes [68, E0, 35, A8, 74, C3]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075141465 2 bytes [14, 75]
.text E:\Downloads\trojanerboard\zio8i03t.exe[6752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751414bb 2 bytes [14, 75]
.text ... * 2
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- --- --- --- Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:44 on 14/10/2013 (Hans-Dieter)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- |