![]() |
win32:zbot-ncp und trojan fakeav hallo. habe wie einige andere wohl einen üblen plagegeist ergattert. hintergrundbild im vista ist verschwunden und ist nun schwarz, ausserdem auch diverse dateien aus privaten ordnern weg und beim hochfahren kommt die fehlermeldung: Catalyst control centre : Host application hat ein problem festgestellt und muss beendet werden hier txt aus otl (die extra wird augenblicklich nicht erstellt, die funktion fix in otl gibt die fehlermeldung: es wurde kein fix vorgesehen) bin für tips dankbar:OTL Logfile: Code: OTL logfile created on: 13.05.2011 22:16:54 - Run 3 hier eine extra von vorhin:OTL Logfile: Code: OTL Extras logfile created on: 13.05.2011 21:46:14 - Run 2 einen malwarebytes report habe ich auch. allerdings ist die malware version ewig alt, ein update wird nach dem download abgebrochen mit fehlermeldung. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6512 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 13.05.2011 21:22:08 mbam-log-2011-05-13 (21-21-53).txt Scan type: Quick scan Objects scanned: 132878 Time elapsed: 4 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Alfred\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery (Trojan.FakeAV) -> No action taken. Files Infected: c:\Users\Alfred\Desktop\windows recovery.lnk (Trojan.FakeAV) -> No action taken. c:\Users\Alfred\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery\uninstall windows recovery.lnk (Trojan.FakeAV) -> No action taken. c:\Users\Alfred\AppData\Roaming\microsoft\Windows\start menu\Programs\windows recovery\windows recovery.lnk (Trojan.FakeAV) -> No action taken. bin für jede hilfe dankbar habs geschafft über ein anderes benutzerkonto malware zu aktualisieren. der neue scan zeigt keine infektkion mehr, aber probleme sind immer noch die gleichen: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6569 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 14.05.2011 00:38:59 mbam-log-2011-05-14 (00-38-59).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 252531 Time elapsed: 48 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
bitte erstelle und poste ein combofix log. Ein Leitfaden und Tutorium zur Nutzung von ComboFix |
hallo markus, habe vor deiner antwort schon ein unhide und ccleaner laufen lassen. danach waren alle funktionen wieder da und der rechner läuft ohne fehlermeldung. ein kompletter scan mit avast zeigt ebenfalls keinen schädling mehr an. da ich ein bisschen respect vor combofix habe bin ich mir nicht sicher ob das noch nötig ist nachdem die anderen progs nichts mehr finden. auch malwarebytes gibt keine bedrohung mehr an. soll ich trotzdem combofix laufen lassen? |
ja sicher. wenn alle programme 100 % aller malware finden würden, hättest du ja kein problem mit trojanern etc gehabt. |
hier der log: Combofix Logfile: Code: ComboFix 11-05-13.03 - spieler 14.05.2011 21:38:12.1.1 - x86 |
poste einen gmer report http://www.trojaner-board.de/74908-a...t-scanner.html |
GMER 1.0.15.15627 - hxxp://www.gmer.net Rootkit scan 2011-05-15 14:32:19 Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 Hitachi_HDT721032SLA360 rev.ST2OA31B Running: g5fylyik.exe; Driver: C:\Users\spieler\AppData\Local\Temp\uwdiqpob.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8E0AF202] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8E0B181C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8E0B1874] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8E0B198A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8E0B1772] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8E0B18C4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8E0B17C6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8E0B1938] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8E0AF226] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8E0AEFF0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8E0AF24A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8E0B1D82] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8E0AFCDA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8E0B184C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8E0B189C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8E0B19B4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8E0B179E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8E0B1904] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8E0B17F4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8E0B1962] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8E0AFBA0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8E0AF26E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8E0AF292] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8E0AF04A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8E0AF186] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8E0AF162] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8E0AF1AA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8E0AF2B6] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8E67C902] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!KeSetEvent + 10D 82AB7890 4 Bytes [02, F2, 0A, 8E] .text ntkrnlpa.exe!KeSetEvent + 1D1 82AB7954 8 Bytes [1C, 18, 0B, 8E, 74, 18, 0B, ...] {SBB AL, 0x18; OR ECX, [ESI-0x71f4e78c]} .text ntkrnlpa.exe!KeSetEvent + 1DD 82AB7960 4 Bytes [8A, 19, 0B, 8E] .text ntkrnlpa.exe!KeSetEvent + 1F5 82AB7978 4 Bytes [72, 17, 0B, 8E] .text ntkrnlpa.exe!KeSetEvent + 215 82AB7998 8 Bytes [C4, 18, 0B, 8E, C6, 17, 0B, ...] {LES EBX, DWORD [EAX]; OR ECX, [ESI-0x71f4e83a]} .text ... PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82BE25C7 5 Bytes JMP 8E6782BE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ObInsertObject 82C3B4F3 5 Bytes JMP 8E679D5C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82C44E18 4 Bytes CALL 8E0B034B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82C48A8C 4 Bytes CALL 8E0B0361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) PAGE ntkrnlpa.exe!ZwCreateProcessEx 82C9CDAE 7 Bytes JMP 8E67C906 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8D60B000, 0x2585E6, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Windows\system32\svchost.exe[12] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[12] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[12] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[12] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[12] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000C0600 .text C:\Windows\system32\svchost.exe[12] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000C0804 .text C:\Windows\system32\svchost.exe[12] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000C0A08 .text C:\Windows\system32\svchost.exe[12] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000C01F8 .text C:\Windows\system32\svchost.exe[12] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000C03FC .text C:\Windows\system32\svchost.exe[208] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[208] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[208] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[208] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[276] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[276] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[276] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[276] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[276] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00220600 .text C:\Windows\system32\svchost.exe[276] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00220804 .text C:\Windows\system32\svchost.exe[276] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00220A08 .text C:\Windows\system32\svchost.exe[276] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 002201F8 .text C:\Windows\system32\svchost.exe[276] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 002203FC .text C:\Windows\System32\svchost.exe[456] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[456] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[456] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\svchost.exe[456] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000F0600 .text C:\Windows\System32\svchost.exe[456] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000F0804 .text C:\Windows\System32\svchost.exe[456] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000F0A08 .text C:\Windows\System32\svchost.exe[456] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000F01F8 .text C:\Windows\System32\svchost.exe[456] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000F03FC .text C:\Windows\System32\svchost.exe[480] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[480] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[480] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[480] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\csrss.exe[508] KERNEL32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\wininit.exe[576] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000301F8 .text C:\Windows\system32\wininit.exe[576] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000303FC .text C:\Windows\system32\wininit.exe[576] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000503FC .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00050600 .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00051014 .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00050804 .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00050A08 .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00050C0C .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00050E10 .text C:\Windows\system32\wininit.exe[576] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000501F8 .text C:\Windows\system32\wininit.exe[576] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00060600 .text C:\Windows\system32\wininit.exe[576] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00060804 .text C:\Windows\system32\wininit.exe[576] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00060A08 .text C:\Windows\system32\wininit.exe[576] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000601F8 .text C:\Windows\system32\wininit.exe[576] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000603FC .text C:\Windows\system32\csrss.exe[584] KERNEL32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[612] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[612] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[612] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000803FC .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00080600 .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00081014 .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00080804 .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00080A08 .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00080C0C .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00080E10 .text C:\Windows\system32\svchost.exe[612] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000801F8 .text C:\Windows\system32\services.exe[620] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\services.exe[620] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\services.exe[620] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\services.exe[620] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\services.exe[620] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00080600 .text C:\Windows\system32\services.exe[620] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00080804 .text C:\Windows\system32\services.exe[620] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00080A08 .text C:\Windows\system32\services.exe[620] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000801F8 .text C:\Windows\system32\services.exe[620] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000803FC .text C:\Windows\system32\lsass.exe[632] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000A01F8 .text C:\Windows\system32\lsass.exe[632] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000A03FC .text C:\Windows\system32\lsass.exe[632] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000C03FC .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 000C0600 .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 000C1014 .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 000C0804 .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 000C0A08 .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 000C0C0C .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 000C0E10 .text C:\Windows\system32\lsass.exe[632] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000C01F8 .text C:\Windows\system32\lsass.exe[632] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000D0600 .text C:\Windows\system32\lsass.exe[632] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000D0804 .text C:\Windows\system32\lsass.exe[632] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000D0A08 .text C:\Windows\system32\lsass.exe[632] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000D01F8 .text C:\Windows\system32\lsass.exe[632] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000D03FC .text C:\Windows\system32\lsm.exe[640] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\lsm.exe[640] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\lsm.exe[640] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\lsm.exe[640] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\winlogon.exe[688] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000301F8 .text C:\Windows\system32\winlogon.exe[688] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000303FC .text C:\Windows\system32\winlogon.exe[688] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000503FC .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00050600 .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00051014 .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00050804 .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00050A08 .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00050C0C .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00050E10 .text C:\Windows\system32\winlogon.exe[688] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000501F8 .text C:\Windows\system32\winlogon.exe[688] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00060600 .text C:\Windows\system32\winlogon.exe[688] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00060804 .text C:\Windows\system32\winlogon.exe[688] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00060A08 .text C:\Windows\system32\winlogon.exe[688] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000601F8 .text C:\Windows\system32\winlogon.exe[688] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000603FC .text C:\Windows\system32\svchost.exe[848] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[848] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[848] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[920] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000C0600 .text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000C0804 .text C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000C0A08 .text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000C01F8 .text C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000C03FC .text C:\Windows\System32\svchost.exe[956] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[956] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[956] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\svchost.exe[956] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 003A0600 .text C:\Windows\System32\svchost.exe[956] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 003A0804 .text C:\Windows\System32\svchost.exe[956] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 003A0A08 .text C:\Windows\System32\svchost.exe[956] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 003A01F8 .text C:\Windows\System32\svchost.exe[956] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 003A03FC .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001501F8 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001503FC .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00190600 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00190804 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00190A08 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001901F8 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001903FC .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001A03FC .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 001A0600 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 001A1014 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 001A0804 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 001A0A08 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 001A0C0C .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 001A0E10 .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[988] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001A01F8 .text C:\Windows\system32\Ati2evxx.exe[1040] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001501F8 .text C:\Windows\system32\Ati2evxx.exe[1040] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001503FC .text C:\Windows\system32\Ati2evxx.exe[1040] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\Ati2evxx.exe[1040] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00270600 .text C:\Windows\system32\Ati2evxx.exe[1040] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00270804 .text C:\Windows\system32\Ati2evxx.exe[1040] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00270A08 .text C:\Windows\system32\Ati2evxx.exe[1040] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 002701F8 .text C:\Windows\system32\Ati2evxx.exe[1040] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 002703FC .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 002803FC .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00280600 .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00281014 .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00280804 .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00280A08 .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00280C0C .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00280E10 .text C:\Windows\system32\Ati2evxx.exe[1040] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 002801F8 .text C:\Windows\System32\svchost.exe[1060] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[1060] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[1060] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[1060] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\svchost.exe[1060] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00110600 .text C:\Windows\System32\svchost.exe[1060] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00110804 .text C:\Windows\System32\svchost.exe[1060] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00110A08 .text C:\Windows\System32\svchost.exe[1060] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001101F8 .text C:\Windows\System32\svchost.exe[1060] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001103FC .text C:\Windows\System32\svchost.exe[1112] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[1112] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[1112] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[1112] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\svchost.exe[1112] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00C90600 .text C:\Windows\System32\svchost.exe[1112] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00C90804 .text C:\Windows\System32\svchost.exe[1112] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00C90A08 .text C:\Windows\System32\svchost.exe[1112] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 00C901F8 .text C:\Windows\System32\svchost.exe[1112] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 00C903FC .text C:\Windows\system32\svchost.exe[1124] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000901F8 .text C:\Windows\system32\svchost.exe[1124] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000903FC .text C:\Windows\system32\svchost.exe[1124] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000B03FC .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 000B0600 .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 000B1014 .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 000B0804 .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 000B0A08 |
.text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 000B0C0C .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 000B0E10 .text C:\Windows\system32\svchost.exe[1124] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000B01F8 .text C:\Windows\system32\svchost.exe[1124] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 002D0600 .text C:\Windows\system32\svchost.exe[1124] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 002D0804 .text C:\Windows\system32\svchost.exe[1124] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 002D0A08 .text C:\Windows\system32\svchost.exe[1124] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 002D01F8 .text C:\Windows\system32\svchost.exe[1124] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 002D03FC .text C:\Windows\system32\AUDIODG.EXE[1196] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\SLsvc.exe[1244] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[1296] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[1296] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[1296] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000803FC .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00080600 .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00081014 .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00080804 .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00080A08 .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00080C0C .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00080E10 .text C:\Windows\system32\svchost.exe[1296] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000801F8 .text C:\Windows\system32\svchost.exe[1296] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00C60600 .text C:\Windows\system32\svchost.exe[1296] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00C60804 .text C:\Windows\system32\svchost.exe[1296] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00C60A08 .text C:\Windows\system32\svchost.exe[1296] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 00C601F8 .text C:\Windows\system32\svchost.exe[1296] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 00C603FC .text C:\Windows\system32\svchost.exe[1416] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[1416] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[1416] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000803FC .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00080600 .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00081014 .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00080804 .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00080A08 .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00080C0C .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00080E10 .text C:\Windows\system32\svchost.exe[1416] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000801F8 .text C:\Windows\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00460600 .text C:\Windows\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00460804 .text C:\Windows\system32\svchost.exe[1416] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00460A08 .text C:\Windows\system32\svchost.exe[1416] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 004601F8 .text C:\Windows\system32\svchost.exe[1416] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 004603FC .text C:\Windows\System32\svchost.exe[1464] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[1464] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[1464] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[1464] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\SearchIndexer.exe[1488] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\SearchIndexer.exe[1488] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\SearchIndexer.exe[1488] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\SearchIndexer.exe[1488] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\SearchIndexer.exe[1488] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00080600 .text C:\Windows\system32\SearchIndexer.exe[1488] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00080804 .text C:\Windows\system32\SearchIndexer.exe[1488] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00080A08 .text C:\Windows\system32\SearchIndexer.exe[1488] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000801F8 .text C:\Windows\system32\SearchIndexer.exe[1488] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000803FC .text C:\Windows\system32\Ati2evxx.exe[1520] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001501F8 .text C:\Windows\system32\Ati2evxx.exe[1520] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001503FC .text C:\Windows\system32\Ati2evxx.exe[1520] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\Ati2evxx.exe[1520] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00170600 .text C:\Windows\system32\Ati2evxx.exe[1520] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00170804 .text C:\Windows\system32\Ati2evxx.exe[1520] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00170A08 .text C:\Windows\system32\Ati2evxx.exe[1520] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001701F8 .text C:\Windows\system32\Ati2evxx.exe[1520] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001703FC .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001803FC .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00180600 .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00181014 .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00180804 .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00180A08 .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00180C0C .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00180E10 .text C:\Windows\system32\Ati2evxx.exe[1520] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001801F8 .text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1572] kernel32.dll!SetUnhandledExceptionFilter 757CA84F 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP } .text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1572] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Users\Alfred\Downloads\g5fylyik.exe[1640] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\spoolsv.exe[1896] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\spoolsv.exe[1896] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\System32\spoolsv.exe[1896] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\spoolsv.exe[1896] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\spoolsv.exe[1896] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000F0600 .text C:\Windows\System32\spoolsv.exe[1896] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000F0804 .text C:\Windows\System32\spoolsv.exe[1896] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000F0A08 .text C:\Windows\System32\spoolsv.exe[1896] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000F01F8 .text C:\Windows\System32\spoolsv.exe[1896] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000F03FC .text C:\Windows\system32\svchost.exe[1920] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[1920] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[1920] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[1920] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[1920] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 001B0600 .text C:\Windows\system32\svchost.exe[1920] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 001B0804 .text C:\Windows\system32\svchost.exe[1920] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 001B0A08 .text C:\Windows\system32\svchost.exe[1920] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001B01F8 .text C:\Windows\system32\svchost.exe[1920] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001B03FC .text C:\Program Files\Alwil Software\Avast5\AvastUI.exe[2068] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\taskeng.exe[2408] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\taskeng.exe[2408] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\taskeng.exe[2408] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\taskeng.exe[2408] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\taskeng.exe[2408] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00090600 .text C:\Windows\system32\taskeng.exe[2408] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00090804 .text C:\Windows\system32\taskeng.exe[2408] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00090A08 .text C:\Windows\system32\taskeng.exe[2408] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000901F8 .text C:\Windows\system32\taskeng.exe[2408] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000903FC .text C:\Windows\system32\ctfmon.exe[2600] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000803FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00080600 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00081014 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00080804 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00080A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00080C0C .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00080E10 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000801F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00090600 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00090804 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00090A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000901F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2864] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000903FC .text C:\Windows\system32\taskeng.exe[2948] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000901F8 .text C:\Windows\system32\taskeng.exe[2948] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000903FC .text C:\Windows\system32\taskeng.exe[2948] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000B03FC .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 000B0600 .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 000B1014 .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 000B0804 .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 000B0A08 .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 000B0C0C .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 000B0E10 .text C:\Windows\system32\taskeng.exe[2948] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000B01F8 .text C:\Windows\system32\taskeng.exe[2948] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000C0600 .text C:\Windows\system32\taskeng.exe[2948] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000C0804 .text C:\Windows\system32\taskeng.exe[2948] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000C0A08 .text C:\Windows\system32\taskeng.exe[2948] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000C01F8 .text C:\Windows\system32\taskeng.exe[2948] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000C03FC .text C:\Windows\system32\Dwm.exe[2956] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\Dwm.exe[2956] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\Dwm.exe[2956] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000803FC .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00080600 .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00081014 .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00080804 .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00080A08 .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00080C0C .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00080E10 .text C:\Windows\system32\Dwm.exe[2956] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000801F8 .text C:\Windows\system32\Dwm.exe[2956] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00090600 .text C:\Windows\system32\Dwm.exe[2956] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00090804 .text C:\Windows\system32\Dwm.exe[2956] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00090A08 .text C:\Windows\system32\Dwm.exe[2956] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000901F8 .text C:\Windows\system32\Dwm.exe[2956] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000903FC .text C:\Windows\Explorer.EXE[3020] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\Explorer.EXE[3020] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\Explorer.EXE[3020] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000B03FC .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 000B0600 .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 000B1014 .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 000B0804 .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 000B0A08 .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 000B0C0C .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 000B0E10 .text C:\Windows\Explorer.EXE[3020] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000B01F8 .text C:\Windows\Explorer.EXE[3020] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 000C0600 .text C:\Windows\Explorer.EXE[3020] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 000C0804 .text C:\Windows\Explorer.EXE[3020] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 000C0A08 .text C:\Windows\Explorer.EXE[3020] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000C01F8 .text C:\Windows\Explorer.EXE[3020] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000C03FC .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001501F8 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001503FC .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001703FC .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00170600 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00171014 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00170804 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00170A08 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00170C0C .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00170E10 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001701F8 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00180600 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00180804 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00180A08 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001801F8 .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3312] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001803FC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001601F8 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001603FC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001703FC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00170600 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00171014 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00170804 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00170A08 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00170C0C .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00170E10 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001701F8 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00180600 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00180804 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00180A08 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001801F8 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3328] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001803FC .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001401F8 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001403FC .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00160600 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00160804 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00160A08 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001601F8 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001603FC .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001703FC .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00170600 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00171014 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00170804 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00170A08 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00170C0C .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00170E10 .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3376] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001701F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000803FC .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00080600 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00081014 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00080804 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00080A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00080C0C .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00080E10 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000801F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00090600 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00090804 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00090A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 000901F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[3492] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 000903FC .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001501F8 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001503FC .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001703FC .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00170600 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00171014 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00170804 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00170A08 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00170C0C .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00170E10 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001701F8 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00BB0600 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00BB0804 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00BB0A08 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 00BB01F8 .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3508] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 00BB03FC .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 001501F8 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 001503FC .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 001703FC .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00170600 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00171014 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00170804 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00170A08 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00170C0C .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00170E10 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 001701F8 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] USER32.dll!SetWindowsHookExA 75E86322 5 Bytes JMP 00180600 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] USER32.dll!SetWindowsHookExW 75E887AD 5 Bytes JMP 00180804 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] USER32.dll!UnhookWindowsHookEx 75E898DB 5 Bytes JMP 00180A08 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] USER32.dll!SetWinEventHook 75E89F3A 5 Bytes JMP 001801F8 .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3516] USER32.dll!UnhookWinEvent 75E8C06F 5 Bytes JMP 001803FC .text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3528] KERNEL32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[4008] ntdll.dll!LdrLoadDll 76EE93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[4008] ntdll.dll!LdrUnloadDll 76EFB740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[4008] kernel32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!CreateServiceW 75FC9EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!DeleteService 75FCA07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!SetServiceObjectSecurity 76006CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!ChangeServiceConfigA 76006DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!ChangeServiceConfigW 76006F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!ChangeServiceConfig2A 76007099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!ChangeServiceConfig2W 760071E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[4008] ADVAPI32.dll!CreateServiceA 760072A1 5 Bytes JMP 000701F8 .text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[4072] KERNEL32.dll!GetBinaryTypeW + 70 757F2247 1 Byte [62] ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\system32\services.exe[620] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 001D0002 IAT C:\Windows\system32\services.exe[620] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 001D0000 IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74087817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [740DA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7408BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7407F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [740875E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7407E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [740B8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7408DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7407FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7407FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [740771CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7410CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [740AC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7407D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74076853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7407687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[3020] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74082AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software) AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0023540e79f3 Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\0023540e79f3 (not active ControlSet) ---- EOF - GMER 1.0.15 ---- |
hier war ein doppelposting, daher gelöscht. |
läuft der pc noch fehlerfrei oder ist noch ein problem aufgetreten? |
hallo marcus, das einzige, was noch nicht wieder da ist ist folgendes: wenn ich auf windows/start gehe erscheinen normalerweise die zuletzt benutzen progs in der sich önnenden leiste. diese ist leer und füllt sich erst mit allen progs wenn ich entsprechend auf "alle programme" klicke (weiß nicht wie ich das besser beschreiben soll. eben unten links das windows logo...) sonst keine fehler mehr aufgetreten, alle dateien und funktionen sind da. gruß |
hmm da weis ich im mom auch keine lösung. lade den ccleaner slim: Piriform - Builds falls der ccleaner bereits instaliert, überspringen. instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten. |
ich bin zufrieden, habe nicht das gefühl, dass da im augenblick noch was dramatisches im hintergrund arbeitet. ich muss jetzt wieder nach hause und werden meinen vater erst einmal so mit dem rechner arbeiten lassen. in 14 tagen bin ich wieder vor ort und werde dann die liste posten. ersteinmal vielen, vielen dank und bis in 2 wochen. gruß |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:22 Uhr. |
Copyright ©2000-2025, Trojaner-Board