dibbel91 | 25.09.2012 23:25 | GMER logfile Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-26 00:10:54
Windows 6.0.6000 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD25 rev.01.0
Running: 7fvpumgp.exe; Driver: C:\Users\Possehl\AppData\Local\Temp\uftdyfoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8D961708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8DC347C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0x8D96211C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8D96CF28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8D96CF74]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8D96D0F6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8D96CE96]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0x8DC34BBA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8D96CEDE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThread [0x8D962310]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8D96D0B0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDebugActiveProcess [0x8D962A9C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8D961756]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDuplicateObject [0x8DC3F808]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8DC348AC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8D9613BE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8D9617A4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8D966456]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8D963464]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8D96CF52]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8D96CF96]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8D96D11A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8D96CEBC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenProcess [0x8DC3F70C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8D96D03A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8D96CF06]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenThread [0x8DC3F78A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8D96D0D4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8DC34A2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8D963330]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueueApcThread [0x8D962EDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8D9617F2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8D961840]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetContextThread [0x8D96291C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8D961448]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8D9615F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8D96159E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendProcess [0x8D962BFE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendThread [0x8D962D5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8D961668]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0x8DC34AF6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwTerminateThread [0x8D962794]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8D96188E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0x8DC34962]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThreadEx [0x8D962498]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8DC4C966]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 734 824811B8 12 Bytes [F2, 17, 96, 8D, 40, 18, 96, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 7E0 82481264 12 Bytes [FE, 2B, 96, 8D, 5A, 2D, 96, ...]
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 825BFD69 4 Bytes CALL 8D963B07 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 825C77DC 4 Bytes CALL 8D963B1D \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 825F2D4B 5 Bytes JMP 8DC49806 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 825F8882 5 Bytes JMP 8DC4B320 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 8261381D 7 Bytes JMP 8DC4C96A \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text win32k.sys!EngMultiByteToUnicodeN + 2B73 95A210FF 1 Byte [E9]
.text win32k.sys!EngMultiByteToUnicodeN + 2B73 95A210FF 5 Bytes JMP 8D966F20 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetRgnData + C9D 95A24F75 5 Bytes JMP 8D966DDA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngSetRectRgn + 3DB 95A25536 5 Bytes JMP 8D966C00 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 4E6 95A52E56 5 Bytes JMP 8D967D3E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTransparentBlt + 37CC 95A5613C 5 Bytes JMP 8D966592 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 323E 95A5BADD 5 Bytes JMP 8D966FB2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XFORMOBJ_iGetXform + 33D0 95A5BC6F 5 Bytes JMP 8D9670A4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + 273B 95A5EA94 5 Bytes JMP 8D966866 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + A684 95A669DD 5 Bytes JMP 8D9679A8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + 11666 95A6D9BF 5 Bytes JMP 8D96648C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + 118A7 95A6DC00 5 Bytes JMP 8D966B40 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + 1197A 95A6DCD3 5 Bytes JMP 8D966E06 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text ...
.text win32k.sys!EngMapFontFileFD + F726 95A80E8E 5 Bytes JMP 8D9666E6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPaint + 3291 95A865F3 5 Bytes JMP 8D967BD8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPaint + 69B2 95A89D14 5 Bytes JMP 8D966756 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngEraseSurface + 5C5 95A8D88B 5 Bytes JMP 8D96708C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 44F5 95AAD01C 5 Bytes JMP 8D9665AA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLpkInstalled + FD1 95AC5B69 5 Bytes JMP 8D96795E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 3BF8 95AD2D59 5 Bytes JMP 8D967DE0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 5E54 95AD4FB5 5 Bytes JMP 8D966FCA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bEnum + AA 95AD57BE 5 Bytes JMP 8D967B20 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStrokePath + CE82 95AE2DC9 5 Bytes JMP 8D967918 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCopyBits + 1DC3 95AE9FE1 5 Bytes JMP 8D967A6E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFindImageProcAddress + 1A09 95AF585B 5 Bytes JMP 8D966A6A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteClip + 5A16 95B0B735 5 Bytes JMP 8D966812 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bPolyBezierTo + 62D 95B13A3F 5 Bytes JMP 8D96693E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1661 95B2959C 5 Bytes JMP 8D966FE2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + 3868 95B313B1 5 Bytes JMP 8D966682 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + 658D 95B340D6 5 Bytes JMP 8D9669D4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 1A89 95B6F6AA 5 Bytes JMP 8D967C96 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Fujitsu Siemens Computers\FSCLounge\FSCWBaseUpdaterService\2\FSCWBaseUpdaterService.exe[12] KERNEL32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[288] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[408] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\csrss.exe[580] KERNEL32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\wininit.exe[636] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text ...
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 001501F8
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 001503FC
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00170A08
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00170600
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00170804
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 001703FC
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 001701F8
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 001803FC
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00180600
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00180A08
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00181014
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00180804
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00180C0C
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00180E10
.text C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe[964] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[968] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\Ati2evxx.exe[1004] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1048] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1076] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text ...
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1556] kernel32.dll!SetUnhandledExceptionFilter 76E8D177 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Windows\ehome\ehtray.exe[1584] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\ehome\ehtray.exe[1584] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\ehome\ehtray.exe[1584] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\ehome\ehtray.exe[1584] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\ehome\ehtray.exe[1584] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00080A08
.text C:\Windows\ehome\ehtray.exe[1584] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00080600
.text C:\Windows\ehome\ehtray.exe[1584] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00080804
.text C:\Windows\ehome\ehtray.exe[1584] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000803FC
.text C:\Windows\ehome\ehtray.exe[1584] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000801F8
.text C:\Windows\system32\Ati2evxx.exe[1624] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\mobsync.exe[1720] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\System32\mobsync.exe[1720] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\System32\mobsync.exe[1720] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\System32\mobsync.exe[1720] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\System32\mobsync.exe[1720] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 000A0A08
.text C:\Windows\System32\mobsync.exe[1720] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 000A0600
.text C:\Windows\System32\mobsync.exe[1720] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 000A0804
.text C:\Windows\System32\mobsync.exe[1720] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000A03FC
.text C:\Windows\System32\mobsync.exe[1720] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000A01F8
.text C:\Windows\System32\spoolsv.exe[1764] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1788] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[1988] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[2056] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2160] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[2160] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[2160] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[2160] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[2160] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 002A0A08
.text C:\Windows\system32\svchost.exe[2160] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 002A0600
.text C:\Windows\system32\svchost.exe[2160] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 002A0804
.text C:\Windows\system32\svchost.exe[2160] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 002A03FC
.text C:\Windows\system32\svchost.exe[2160] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 002A01F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 001A03FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 001A0600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 001A0A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 001A1014
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 001A0804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 001A0C0C
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 001A0E10
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 001A01F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 001B0A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 001B0600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 001B0804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 001B03FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2268] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 001B01F8
.text C:\Windows\System32\svchost.exe[2284] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[2284] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[2284] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[2284] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[2284] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 000C0A08
.text C:\Windows\System32\svchost.exe[2284] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 000C0600
.text C:\Windows\System32\svchost.exe[2284] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 000C0804
.text C:\Windows\System32\svchost.exe[2284] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000C03FC
.text C:\Windows\System32\svchost.exe[2284] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000C01F8
.text C:\Windows\System32\svchost.exe[2316] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[2316] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[2316] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[2316] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[2328] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000901F8
.text C:\Windows\system32\svchost.exe[2328] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000903FC
.text C:\Windows\system32\svchost.exe[2328] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000B03FC
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 000B0600
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 000B0A08
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 000B1014
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 000B0804
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 000B0E10
.text C:\Windows\system32\svchost.exe[2328] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000B01F8
.text C:\Windows\system32\svchost.exe[2328] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 000E0A08
.text C:\Windows\system32\svchost.exe[2328] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 000E0600
.text C:\Windows\system32\svchost.exe[2328] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 000E0804
.text C:\Windows\system32\svchost.exe[2328] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000E03FC
.text C:\Windows\system32\svchost.exe[2328] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000E01F8
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 001401F8
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 001403FC
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00260A08
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00260600
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00260804
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 002603FC
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 002601F8
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 002703FC
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00270600
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00270A08
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00271014
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00270804
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00270C0C
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00270E10
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[2340] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 002701F8
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[2612] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[2612] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00C00A08
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00C00600
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00C00804
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 00C003FC
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 00C001F8
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 001501F8
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 001503FC
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 001703FC
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00170600
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00170A08
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00171014
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00170804
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00170C0C
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00170E10
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 001701F8
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00180A08
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00180600
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00180804
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 001803FC
.text C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe[2700] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 001801F8
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 001501F8
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 001503FC
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00170A08
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00170600
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00170804
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 001703FC
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 001701F8
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 001803FC
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00180600
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00180A08
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00181014
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00180804
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00180C0C
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00180E10
.text C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe[2768] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 001801F8
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00070A08
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00070600
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00070804
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000703FC
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000701F8
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000803FC
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00080600
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00080A08
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00081014
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00080804
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00080C0C
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00080E10
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2800] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000801F8
.text C:\Windows\System32\svchost.exe[2844] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[2844] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[2844] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000B03FC
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 000B0600
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 000B0A08
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 000B1014
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 000B0804
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 000B0C0C
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 000B0E10
.text C:\Windows\System32\svchost.exe[2844] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000B01F8
.text C:\Windows\system32\SearchIndexer.exe[2864] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchIndexer.exe[2864] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchIndexer.exe[2864] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\system32\SearchIndexer.exe[2864] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\system32\SearchIndexer.exe[2864] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00080A08
.text C:\Windows\system32\SearchIndexer.exe[2864] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00080600
.text C:\Windows\system32\SearchIndexer.exe[2864] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00080804
.text C:\Windows\system32\SearchIndexer.exe[2864] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000803FC
.text C:\Windows\system32\SearchIndexer.exe[2864] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000801F8
.text C:\Windows\system32\taskeng.exe[2972] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskeng.exe[2972] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskeng.exe[2972] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\system32\taskeng.exe[2972] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\system32\taskeng.exe[2972] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00080A08
.text C:\Windows\system32\taskeng.exe[2972] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00080600
.text C:\Windows\system32\taskeng.exe[2972] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00080804
.text C:\Windows\system32\taskeng.exe[2972] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000803FC
.text C:\Windows\system32\taskeng.exe[2972] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000801F8
.text C:\Windows\system32\Dwm.exe[2976] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\system32\Dwm.exe[2976] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\system32\Dwm.exe[2976] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000703FC
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00070600
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00070A08
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00071014
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00070804
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00070C0C
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00070E10
.text C:\Windows\system32\Dwm.exe[2976] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000701F8
.text C:\Windows\system32\Dwm.exe[2976] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00080A08
.text C:\Windows\system32\Dwm.exe[2976] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00080600
.text C:\Windows\system32\Dwm.exe[2976] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00080804
.text C:\Windows\system32\Dwm.exe[2976] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000803FC
.text C:\Windows\system32\Dwm.exe[2976] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000801F8
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 001601F8
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 001603FC
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00170A08
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00170600
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00170804
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 001703FC
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 001701F8
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 001803FC
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00180600
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00180A08
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00181014
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00180804
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00180C0C
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00180E10
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[2984] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 001801F8
.text C:\Windows\Explorer.EXE[2988] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Windows\Explorer.EXE[2988] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Windows\Explorer.EXE[2988] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000B03FC
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 000B0600
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 000B0A08
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 000B1014
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 000B0804
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 000B0C0C
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 000B0E10
.text C:\Windows\Explorer.EXE[2988] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000B01F8
.text C:\Windows\Explorer.EXE[2988] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 000C0A08
.text C:\Windows\Explorer.EXE[2988] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 000C0600
.text C:\Windows\Explorer.EXE[2988] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 000C0804
.text C:\Windows\Explorer.EXE[2988] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000C03FC
.text C:\Windows\Explorer.EXE[2988] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000C01F8
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00070A08
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00070600
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00070804
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 000703FC
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 000701F8
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000803FC
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00080600
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00080A08
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00081014
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00080804
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00080C0C
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00080E10
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[3028] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000801F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000501F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000503FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!CreateServiceW 77768686 5 Bytes JMP 000903FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!DeleteService 77768788 5 Bytes JMP 00090600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!ChangeServiceConfigW 7776A26A 5 Bytes JMP 00090A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!SetServiceObjectSecurity 777A3791 5 Bytes JMP 00091014
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!ChangeServiceConfigA 777A3891 5 Bytes JMP 00090804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!ChangeServiceConfig2A 777A3A39 5 Bytes JMP 00090C0C
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!ChangeServiceConfig2W 777A3B81 5 Bytes JMP 00090E10
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] ADVAPI32.dll!CreateServiceA 777A3C41 5 Bytes JMP 000901F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] USER32.dll!UnhookWindowsHookEx 77507CE7 5 Bytes JMP 00A30A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] USER32.dll!SetWindowsHookExA 7750891A 5 Bytes JMP 00A30600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] USER32.dll!SetWindowsHookExW 7750913D 5 Bytes JMP 00A30804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] USER32.dll!UnhookWinEvent 77512C03 5 Bytes JMP 00A303FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3084] USER32.dll!SetWinEventHook 77519BFD 5 Bytes JMP 00A301F8
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!LdrLoadDll 775CEB00 5 Bytes JMP 000701F8
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!LdrUnloadDll 775DBF0A 5 Bytes JMP 000703FC
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateFile + 6 775FF41A 4 Bytes [28, 00, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateFile + B 775FF41F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateKey + 6 775FF45A 4 Bytes [68, 01, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateKey + B 775FF45F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateMutant + 6 775FF48A 4 Bytes [28, 02, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateMutant + B 775FF48F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateSection + 6 775FF50A 4 Bytes [68, 02, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtCreateSection + B 775FF50F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtMapViewOfSection + 6 775FFB6A 4 Bytes [A8, 04, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtMapViewOfSection + B 775FFB6F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenFile + 6 775FFBFA 4 Bytes [68, 00, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenFile + B 775FFBFF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenKey + 6 775FFC2A 4 Bytes [A8, 01, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenKey + B 775FFC2F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenMutant + 6 775FFC4A 4 Bytes CALL 76600250 C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenMutant + B 775FFC4F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcess + 6 775FFC7A 1 Byte [28]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcess + 6 775FFC7A 4 Bytes [28, 03, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcess + B 775FFC7F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcessToken + 6 775FFC8A 1 Byte [68]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcessToken + 6 775FFC8A 4 Bytes [68, 03, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcessToken + B 775FFC8F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcessTokenEx + 6 775FFC9A 4 Bytes [28, 04, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenProcessTokenEx + B 775FFC9F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenSection + 6 775FFCAA 4 Bytes [A8, 02, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenSection + B 775FFCAF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThread + 6 775FFCEA 4 Bytes CALL 766002F1 C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThread + B 775FFCEF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThreadToken + 6 775FFCFA 1 Byte [E8]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThreadToken + 6 775FFCFA 4 Bytes CALL 76600302 C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThreadToken + B 775FFCFF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThreadTokenEx + 6 775FFD0A 4 Bytes [68, 04, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtOpenThreadTokenEx + B 775FFD0F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtQueryAttributesFile + 6 775FFD9A 4 Bytes [A8, 00, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtQueryAttributesFile + B 775FFD9F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtQueryFullAttributesFile + 6 775FFE4A 4 Bytes CALL 7660044F C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtQueryFullAttributesFile + B 775FFE4F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtSetInformationFile + 6 7760036A 4 Bytes [28, 01, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtSetInformationFile + B 7760036F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtSetInformationThread + 6 776003BA 1 Byte [A8]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtSetInformationThread + 6 776003BA 4 Bytes [A8, 03, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtSetInformationThread + B 776003BF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtUnmapViewOfSection + 6 7760065A 4 Bytes CALL 76600C63 C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] ntdll.dll!NtUnmapViewOfSection + B 7760065F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] kernel32.dll!CreateProcessW 76E61D27 5 Bytes JMP 000100B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] kernel32.dll!CreateProcessA 76E61D5C 5 Bytes JMP 000100F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] kernel32.dll!OpenEventW 76E84CB8 5 Bytes JMP 00010070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] kernel32.dll!GetBinaryTypeW + 70 76E8714D 1 Byte [62]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] kernel32.dll!CreateEventW 76E89146 5 Bytes JMP 00010030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!DeleteObject 76FD5A1F 5 Bytes JMP 001A01B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!GetDeviceCaps 76FD5EA6 5 Bytes JMP 001A03B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SelectObject 76FD5FC0 5 Bytes JMP 001A05F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SetBkMode 76FD6390 5 Bytes JMP 001A08F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SetTextColor 76FD64BF 5 Bytes JMP 001A0A30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SetStretchBltMode 76FD6624 5 Bytes JMP 001A06B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!DeleteDC 76FD69A5 5 Bytes JMP 001A0170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!StretchDIBits 76FD6F0F 5 Bytes JMP 001A0770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!GetTextMetricsW 76FD720B 5 Bytes JMP 001A0E30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!GetCurrentObject 76FD7419 5 Bytes JMP 001A0370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!RestoreDC 76FD74AA 5 Bytes JMP 001A0530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SaveDC 76FD7557 5 Bytes JMP 001A0570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!GetTextAlign 76FD7A93 5 Bytes JMP 001A0D70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!ExtSelectClipRgn 76FD7AE2 5 Bytes JMP 001A02F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SelectClipRgn 76FD7BED 5 Bytes JMP 001A05B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SetTextAlign 76FD7E09 5 Bytes JMP 001A09F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!IntersectClipRect 76FD82B4 5 Bytes JMP 001A03F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!SetICMMode 76FD88BB 5 Bytes JMP 001A0DB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe[3096] GDI32.dll!ExtTextOutW 76FD89EC 5 Bytes JMP 001A0970 |