GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-03 15:31:19
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Carlos\LOCALS~1\Temp\pgtdipoc.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwAssignProcessToJobObject [0xAAF301CC]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwClose [0xAA6B0435]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwCreateFile [0xAA6AFC5C]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwCreateKey [0xAA6AC0B0]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwCreateProcess [0xAA6AF031]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwCreateProcessEx [0xAA6AEEAE]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwCreateThread [0xAAF30206]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwDeleteFile [0xAA6B04B5]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwDeleteKey [0xAA6AC4E1]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwDeleteValueKey [0xAA6AC574]
SSDT            \SystemRoot\system32\drivers\khips.sys                                                                                                                                                                                                                                                                                 ZwLoadDriver [0xAA4EA8B0]
SSDT            \SystemRoot\system32\drivers\khips.sys                                                                                                                                                                                                                                                                                 ZwMapViewOfSection [0xAA4EAA20]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwOpenFile [0xAA6AFF27]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwOpenKey [0xAA6AC307]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwOpenProcess [0xAAF3051A]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwOpenThread [0xAAF303F6]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwProtectVirtualMemory [0xAAF30292]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwResumeThread [0xAA6AF71F]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwSetContextThread [0xAAF3018E]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwSetInformationFile [0xAA6B0229]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwSetValueKey [0xAA6AC67D]
SSDT            866886D0                                                                                                                                                                                                                                                                                                               ZwSuspendProcess
SSDT            866884F0                                                                                                                                                                                                                                                                                                               ZwSuspendThread
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwTerminateProcess [0xAAF3064E]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwTerminateThread [0xAAF30316]
SSDT            \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)                                                                                                                                                                                                                                                            ZwWriteFile [0xAA6B0186]
SSDT            \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx)                                                                                                                                                                                                                                                 ZwWriteVirtualMemory [0xAAF3034E]

---- Kernel code sections - GMER 1.0.15 ----

PAGENDSM        NDIS.sys!NdisMIndicateStatus                                                                                                                                                                                                                                                                                           F7220A5F 6 Bytes  JMP AA6A41EC \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)

---- User code sections - GMER 1.0.15 ----

.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00130090 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00130694 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 001302C0 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00130234 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00130004 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0013011C 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 001304F0 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0013057C 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 001303D8 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00130464 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00130608 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\WINDOWS\System32\TUProgSt.exe[192] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00130720 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                     7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                       7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                   7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                       7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                       7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                         7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                       7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                   7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!CreateThread                                                                                                                                                                                                                                                         7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                               7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                               7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!WinExec                                                                                                                                                                                                                                                              7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\wuauclt.exe[524] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                     7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\wuauclt.exe[524] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                      7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\wuauclt.exe[524] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                      7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\wuauclt.exe[524] WS2_32.dll!socket                                                                                                                                                                                                                                                                 71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\wuauclt.exe[524] WS2_32.dll!bind                                                                                                                                                                                                                                                                   71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\wuauclt.exe[524] WS2_32.dll!connect                                                                                                                                                                                                                                                                71A9406A 5 Bytes  JMP 00080950 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                              7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                            7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                  7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                            7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!CreateThread                                                                                                                                                                                                                                  7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                        7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                        7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!WinExec                                                                                                                                                                                                                                       7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] kernel32.dll!SetThreadContext                                                                                                                                                                                                                              7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                               7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                               7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] WS2_32.dll!socket                                                                                                                                                                                                                                          71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] WS2_32.dll!bind                                                                                                                                                                                                                                            71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[532] WS2_32.dll!connect                                                                                                                                                                                                                                         71A9406A 5 Bytes  JMP 00130950 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!VirtualProtectEx                                                                                                                                                                                                                                                       7C801A5D 5 Bytes  JMP 001601A8 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!VirtualProtect                                                                                                                                                                                                                                                         7C801AD0 5 Bytes  JMP 00160090 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!WriteProcessMemory                                                                                                                                                                                                                                                     7C80220F 5 Bytes  JMP 00160694 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!CreateProcessW                                                                                                                                                                                                                                                         7C802332 5 Bytes  JMP 001602C0 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!CreateProcessA                                                                                                                                                                                                                                                         7C802367 5 Bytes  JMP 00160234 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!VirtualAlloc                                                                                                                                                                                                                                                           7C809A61 5 Bytes  JMP 00160004 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!VirtualAllocEx                                                                                                                                                                                                                                                         7C809A82 5 Bytes  JMP 0016011C 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!CreateRemoteThread                                                                                                                                                                                                                                                     7C81043C 5 Bytes  JMP 001604F0 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!CreateThread                                                                                                                                                                                                                                                           7C810647 5 Bytes  JMP 0016057C 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                 7C819527 5 Bytes  JMP 001603D8 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                 7C81DDE6 5 Bytes  JMP 0016034C 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!WinExec                                                                                                                                                                                                                                                                7C86158D 5 Bytes  JMP 00160464 
.text           C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!SetThreadContext                                                                                                                                                                                                                                                       7C862C89 5 Bytes  JMP 00160608 
.text           C:\WINDOWS\system32\csrss.exe[932] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                        7E37DDB5 5 Bytes  JMP 001607AC 
.text           C:\WINDOWS\system32\csrss.exe[932] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                        7E3811D1 5 Bytes  JMP 00160720 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000701A8 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00070090 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00070694 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000702C0 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00070234 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00070004 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0007011C 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000704F0 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0007057C 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000703D8 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0007034C 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00070464 
.text           C:\WINDOWS\system32\winlogon.exe[968] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00070608 
.text           C:\WINDOWS\system32\winlogon.exe[968] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000707AC 
.text           C:\WINDOWS\system32\winlogon.exe[968] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00070720 
.text           C:\WINDOWS\system32\winlogon.exe[968] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000708C4 
.text           C:\WINDOWS\system32\winlogon.exe[968] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00070838 
.text           C:\WINDOWS\system32\winlogon.exe[968] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00070950 
.text           C:\WINDOWS\system32\winlogon.exe[968] WININET.dll!InternetConnectA                                                                                                                                                                                                                                                     40C1DEAE 5 Bytes  JMP 00070F54 
.text           C:\WINDOWS\system32\winlogon.exe[968] WININET.dll!InternetConnectW                                                                                                                                                                                                                                                     40C1F862 5 Bytes  JMP 00070FE0 
.text           C:\WINDOWS\system32\winlogon.exe[968] WININET.dll!InternetOpenA                                                                                                                                                                                                                                                        40C2D690 5 Bytes  JMP 00070D24 
.text           C:\WINDOWS\system32\winlogon.exe[968] WININET.dll!InternetOpenW                                                                                                                                                                                                                                                        40C2DB09 5 Bytes  JMP 00070DB0 
.text           C:\WINDOWS\system32\winlogon.exe[968] WININET.dll!InternetOpenUrlA                                                                                                                                                                                                                                                     40C2F3A4 5 Bytes  JMP 00070E3C 
.text           C:\WINDOWS\system32\winlogon.exe[968] WININET.dll!InternetOpenUrlW                                                                                                                                                                                                                                                     40C76DDF 5 Bytes  JMP 00070EC8 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                   7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                     7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                 7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                     7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                     7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                       7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                     7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                 7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!CreateThread                                                                                                                                                                                                                                                       7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                             7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                             7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!WinExec                                                                                                                                                                                                                                                            7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\services.exe[1028] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                   7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\services.exe[1028] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                    7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\services.exe[1028] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                    7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\services.exe[1028] WS2_32.dll!socket                                                                                                                                                                                                                                                               71A93B91 5 Bytes  JMP 001308C4 
.text           C:\WINDOWS\system32\services.exe[1028] WS2_32.dll!bind                                                                                                                                                                                                                                                                 71A93E00 5 Bytes  JMP 00130838 
.text           C:\WINDOWS\system32\services.exe[1028] WS2_32.dll!connect                                                                                                                                                                                                                                                              71A9406A 5 Bytes  JMP 00130950 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                      7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                        7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                    7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                        7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                        7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                          7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                        7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                    7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!CreateThread                                                                                                                                                                                                                                                          7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!WinExec                                                                                                                                                                                                                                                               7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\lsass.exe[1040] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                      7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                       7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                       7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\lsass.exe[1040] WS2_32.dll!socket                                                                                                                                                                                                                                                                  71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\lsass.exe[1040] WS2_32.dll!bind                                                                                                                                                                                                                                                                    71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\lsass.exe[1040] WS2_32.dll!connect                                                                                                                                                                                                                                                                 71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                   7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                     7C801AD0 5 Bytes  JMP 00130090 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                 7C80220F 5 Bytes  JMP 00130694 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                     7C802332 5 Bytes  JMP 001302C0 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                     7C802367 5 Bytes  JMP 00130234 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                       7C809A61 5 Bytes  JMP 00130004 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                     7C809A82 5 Bytes  JMP 0013011C 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                 7C81043C 5 Bytes  JMP 001304F0 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!CreateThread                                                                                                                                                                                                                                                       7C810647 5 Bytes  JMP 0013057C 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                             7C819527 5 Bytes  JMP 001303D8 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                             7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!WinExec                                                                                                                                                                                                                                                            7C86158D 5 Bytes  JMP 00130464 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                   7C862C89 5 Bytes  JMP 00130608 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                    7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1204] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                    7E3811D1 5 Bytes  JMP 00130720 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\svchost.exe[1220] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\svchost.exe[1220] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\svchost.exe[1220] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\svchost.exe[1220] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\svchost.exe[1220] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\svchost.exe[1220] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\svchost.exe[1296] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\svchost.exe[1296] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\svchost.exe[1296] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\svchost.exe[1296] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\svchost.exe[1296] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\svchost.exe[1296] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\System32\svchost.exe[1344] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\System32\svchost.exe[1344] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\System32\svchost.exe[1344] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\System32\svchost.exe[1344] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\System32\svchost.exe[1344] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\System32\svchost.exe[1344] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\System32\svchost.exe[1344] WININET.dll!InternetConnectA                                                                                                                                                                                                                                                     40C1DEAE 5 Bytes  JMP 00080F54 
.text           C:\WINDOWS\System32\svchost.exe[1344] WININET.dll!InternetConnectW                                                                                                                                                                                                                                                     40C1F862 5 Bytes  JMP 00080FE0 
.text           C:\WINDOWS\System32\svchost.exe[1344] WININET.dll!InternetOpenA                                                                                                                                                                                                                                                        40C2D690 5 Bytes  JMP 00080D24 
.text           C:\WINDOWS\System32\svchost.exe[1344] WININET.dll!InternetOpenW                                                                                                                                                                                                                                                        40C2DB09 5 Bytes  JMP 00080DB0 
.text           C:\WINDOWS\System32\svchost.exe[1344] WININET.dll!InternetOpenUrlA                                                                                                                                                                                                                                                     40C2F3A4 5 Bytes  JMP 00080E3C 
.text           C:\WINDOWS\System32\svchost.exe[1344] WININET.dll!InternetOpenUrlW                                                                                                                                                                                                                                                     40C76DDF 5 Bytes  JMP 00080EC8 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\svchost.exe[1432] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\svchost.exe[1432] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\svchost.exe[1432] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\svchost.exe[1432] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                   7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                     7C801AD0 5 Bytes  JMP 00130090 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                 7C80220F 5 Bytes  JMP 00130694 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                     7C802332 5 Bytes  JMP 001302C0 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                     7C802367 5 Bytes  JMP 00130234 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                       7C809A61 5 Bytes  JMP 00130004 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                     7C809A82 5 Bytes  JMP 0013011C 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                 7C81043C 5 Bytes  JMP 001304F0 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!CreateThread                                                                                                                                                                                                                                                       7C810647 5 Bytes  JMP 0013057C 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                             7C819527 5 Bytes  JMP 001303D8 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                             7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!WinExec                                                                                                                                                                                                                                                            7C86158D 5 Bytes  JMP 00130464 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                   7C862C89 5 Bytes  JMP 00130608 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                    7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\WINDOWS\system32\Ati2evxx.exe[1452] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                    7E3811D1 5 Bytes  JMP 00130720 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\svchost.exe[1564] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\svchost.exe[1564] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\svchost.exe[1564] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] WS2_32.dll!socket                                                                                                                                                                                                                                                                71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] WS2_32.dll!bind                                                                                                                                                                                                                                                                  71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\spoolsv.exe[1628] WS2_32.dll!connect                                                                                                                                                                                                                                                               71A9406A 5 Bytes  JMP 00080950 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                      7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                        7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                    7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                        7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                        7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                          7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                        7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                    7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!CreateThread                                                                                                                                                                                                                                          7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!WinExec                                                                                                                                                                                                                                               7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                      7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                       7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                       7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] WS2_32.dll!socket                                                                                                                                                                                                                                                  71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] WS2_32.dll!bind                                                                                                                                                                                                                                                    71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\a-squared Free\a2service.exe[1676] WS2_32.dll!connect                                                                                                                                                                                                                                                 71A9406A 5 Bytes  JMP 00130950 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                        7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!VirtualProtect                                                                                                                                                                                                                          7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                      7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!CreateProcessW                                                                                                                                                                                                                          7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!CreateProcessA                                                                                                                                                                                                                          7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                            7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                          7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                      7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!CreateThread                                                                                                                                                                                                                            7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                  7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                  7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!WinExec                                                                                                                                                                                                                                 7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] kernel32.dll!SetThreadContext                                                                                                                                                                                                                        7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                         7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe[1728] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                         7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                  7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                              7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                  7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                  7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                    7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                  7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                              7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!CreateThread                                                                                                                                                                                                                                    7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                          7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                          7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!SetUnhandledExceptionFilter                                                                                                                                                                                                                     7C8447ED 4 Bytes  [C2, 04, 00, 00]
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!WinExec                                                                                                                                                                                                                                         7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] WS2_32.dll!socket                                                                                                                                                                                                                                            71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] WS2_32.dll!bind                                                                                                                                                                                                                                              71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] WS2_32.dll!connect                                                                                                                                                                                                                                           71A9406A 5 Bytes  JMP 00130950 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                 7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1768] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                 7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                  7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!VirtualProtect                                                                                                                                                                                                                    7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!CreateProcessW                                                                                                                                                                                                                    7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!CreateProcessA                                                                                                                                                                                                                    7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                      7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                    7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!CreateThread                                                                                                                                                                                                                      7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                            7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                            7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!WinExec                                                                                                                                                                                                                           7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] kernel32.dll!SetThreadContext                                                                                                                                                                                                                  7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                   7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe[1812] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                   7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                             7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                               7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                           7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                               7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                               7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                 7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                               7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                           7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!CreateThread                                                                                                                                                                                                                                                 7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                       7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                       7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!WinExec                                                                                                                                                                                                                                                      7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                             7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] WS2_32.dll!socket                                                                                                                                                                                                                                                         71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] WS2_32.dll!bind                                                                                                                                                                                                                                                           71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] WS2_32.dll!connect                                                                                                                                                                                                                                                        71A9406A 5 Bytes  JMP 00130950 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                              7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\Java\jre6\bin\jqs.exe[1832] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                              7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                              7C801A5D 5 Bytes  JMP 000301A8 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                7C801AD0 5 Bytes  JMP 00030090 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                            7C80220F 5 Bytes  JMP 00030694 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                7C802332 5 Bytes  JMP 000302C0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                7C802367 5 Bytes  JMP 00030234 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                  7C809A61 5 Bytes  JMP 00030004 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                7C809A82 5 Bytes  JMP 0003011C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                            7C81043C 5 Bytes  JMP 000304F0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!CreateThread                                                                                                                                                                                                                                  7C810647 5 Bytes  JMP 0003057C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                        7C819527 5 Bytes  JMP 000303D8 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                        7C81DDE6 5 Bytes  JMP 0003034C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!WinExec                                                                                                                                                                                                                                       7C86158D 5 Bytes  JMP 00030464 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] kernel32.dll!SetThreadContext                                                                                                                                                                                                                              7C862C89 5 Bytes  JMP 00030608 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WS2_32.dll!socket                                                                                                                                                                                                                                          71A93B91 5 Bytes  JMP 000308C4 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WS2_32.dll!bind                                                                                                                                                                                                                                            71A93E00 5 Bytes  JMP 00030838 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WS2_32.dll!connect                                                                                                                                                                                                                                         71A9406A 5 Bytes  JMP 00030950 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                               7E37DDB5 5 Bytes  JMP 000307AC 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                               7E3811D1 5 Bytes  JMP 00030720 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WININET.dll!InternetConnectA                                                                                                                                                                                                                               40C1DEAE 5 Bytes  JMP 00030F54 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WININET.dll!InternetConnectW                                                                                                                                                                                                                               40C1F862 5 Bytes  JMP 00030FE0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WININET.dll!InternetOpenA                                                                                                                                                                                                                                  40C2D690 5 Bytes  JMP 00030D24 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WININET.dll!InternetOpenW                                                                                                                                                                                                                                  40C2DB09 5 Bytes  JMP 00030DB0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WININET.dll!InternetOpenUrlA                                                                                                                                                                                                                               40C2F3A4 5 Bytes  JMP 00030E3C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[1868] WININET.dll!InternetOpenUrlW                                                                                                                                                                                                                               40C76DDF 5 Bytes  JMP 00030EC8 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                  7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                    7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                    7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                    7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                      7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                    7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!CreateThread                                                                                                                                                                                                                                      7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                            7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                            7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!WinExec                                                                                                                                                                                                                                           7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                  7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                   7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\O2Micro Oz128 Driver\o2flash.exe[1908] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                   7E3811D1 5 Bytes  JMP 00130720 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                    7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                      7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                  7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                      7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                      7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                        7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                      7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                  7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!CreateThread                                                                                                                                                                                                                                                        7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                              7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                              7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!WinExec                                                                                                                                                                                                                                                             7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\svchost.exe[1996] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                    7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\svchost.exe[1996] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                     7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\svchost.exe[1996] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                     7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                            7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                              7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                          7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                              7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                              7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                                7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                              7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                          7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!CreateThread                                                                                                                                                                                                                                                                7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                      7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                      7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!WinExec                                                                                                                                                                                                                                                                     7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\Explorer.EXE[2068] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                            7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\Explorer.EXE[2068] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                             7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\Explorer.EXE[2068] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                             7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\Explorer.EXE[2068] WININET.dll!InternetConnectA                                                                                                                                                                                                                                                             40C1DEAE 5 Bytes  JMP 00080F54 
.text           C:\WINDOWS\Explorer.EXE[2068] WININET.dll!InternetConnectW                                                                                                                                                                                                                                                             40C1F862 5 Bytes  JMP 00080FE0 
.text           C:\WINDOWS\Explorer.EXE[2068] WININET.dll!InternetOpenA                                                                                                                                                                                                                                                                40C2D690 5 Bytes  JMP 00080D24 
.text           C:\WINDOWS\Explorer.EXE[2068] WININET.dll!InternetOpenW                                                                                                                                                                                                                                                                40C2DB09 5 Bytes  JMP 00080DB0 
.text           C:\WINDOWS\Explorer.EXE[2068] WININET.dll!InternetOpenUrlA                                                                                                                                                                                                                                                             40C2F3A4 5 Bytes  JMP 00080E3C 
.text           C:\WINDOWS\Explorer.EXE[2068] WININET.dll!InternetOpenUrlW                                                                                                                                                                                                                                                             40C76DDF 5 Bytes  JMP 00080EC8 
.text           C:\WINDOWS\Explorer.EXE[2068] WS2_32.dll!socket                                                                                                                                                                                                                                                                        71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\Explorer.EXE[2068] WS2_32.dll!bind                                                                                                                                                                                                                                                                          71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\Explorer.EXE[2068] WS2_32.dll!connect                                                                                                                                                                                                                                                                       71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                        7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                          7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                      7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                          7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                          7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                            7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                          7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                      7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!CreateThread                                                                                                                                                                                                                                                            7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                  7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                  7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!WinExec                                                                                                                                                                                                                                                                 7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\System32\alg.exe[2124] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                        7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\System32\alg.exe[2124] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                         7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\System32\alg.exe[2124] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                         7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\System32\alg.exe[2124] WS2_32.dll!socket                                                                                                                                                                                                                                                                    71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\System32\alg.exe[2124] WS2_32.dll!bind                                                                                                                                                                                                                                                                      71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\System32\alg.exe[2124] WS2_32.dll!connect                                                                                                                                                                                                                                                                   71A9406A 5 Bytes  JMP 00080950 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                              7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                            7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                  7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                            7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!CreateThread                                                                                                                                                                                                                                                  7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                        7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                        7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!WinExec                                                                                                                                                                                                                                                       7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                              7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                               7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                               7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] WS2_32.dll!socket                                                                                                                                                                                                                                                          71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] WS2_32.dll!bind                                                                                                                                                                                                                                                            71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\wbem\wmiprvse.exe[2148] WS2_32.dll!connect                                                                                                                                                                                                                                                         71A9406A 5 Bytes  JMP 00080950 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                     7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                       7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                   7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                       7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                       7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                         7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                       7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                   7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!CreateThread                                                                                                                                                                                                                                         7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                               7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                               7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!WinExec                                                                                                                                                                                                                                              7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                     7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] WS2_32.dll!socket                                                                                                                                                                                                                                                 71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] WS2_32.dll!bind                                                                                                                                                                                                                                                   71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] WS2_32.dll!connect                                                                                                                                                                                                                                                71A9406A 5 Bytes  JMP 00130950 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                      7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\TortoiseSVN\bin\TSVNCache.exe[2364] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                      7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                             7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!VirtualProtect                                                                                                                                                                                                                               7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                           7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!CreateProcessW                                                                                                                                                                                                                               7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!CreateProcessA                                                                                                                                                                                                                               7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                 7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                               7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                           7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!CreateThread                                                                                                                                                                                                                                 7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                       7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                       7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!WinExec                                                                                                                                                                                                                                      7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] kernel32.dll!SetThreadContext                                                                                                                                                                                                                             7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                              7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                              7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] WS2_32.dll!socket                                                                                                                                                                                                                                         71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] WS2_32.dll!bind                                                                                                                                                                                                                                           71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe[2428] WS2_32.dll!connect                                                                                                                                                                                                                                        71A9406A 5 Bytes  JMP 00130950 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                            7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                              7C801AD0 5 Bytes  JMP 00130090 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                          7C80220F 5 Bytes  JMP 00130694 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                              7C802332 5 Bytes  JMP 001302C0 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                              7C802367 5 Bytes  JMP 00130234 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                                7C809A61 5 Bytes  JMP 00130004 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                              7C809A82 5 Bytes  JMP 0013011C 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                          7C81043C 5 Bytes  JMP 001304F0 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!CreateThread                                                                                                                                                                                                                                                                7C810647 5 Bytes  JMP 0013057C 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                      7C819527 5 Bytes  JMP 001303D8 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                      7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!WinExec                                                                                                                                                                                                                                                                     7C86158D 5 Bytes  JMP 00130464 
.text           C:\WINDOWS\vsnp2std.exe[3172] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                            7C862C89 5 Bytes  JMP 00130608 
.text           C:\WINDOWS\vsnp2std.exe[3172] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                             7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\WINDOWS\vsnp2std.exe[3172] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                             7E3811D1 5 Bytes  JMP 00130720 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                             7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                               7C801AD0 5 Bytes  JMP 00130090 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                           7C80220F 5 Bytes  JMP 00130694 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                               7C802332 5 Bytes  JMP 001302C0 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                               7C802367 5 Bytes  JMP 00130234 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                                 7C809A61 5 Bytes  JMP 00130004 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                               7C809A82 5 Bytes  JMP 0013011C 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                           7C81043C 5 Bytes  JMP 001304F0 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!CreateThread                                                                                                                                                                                                                                                                 7C810647 5 Bytes  JMP 0013057C 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                       7C819527 5 Bytes  JMP 001303D8 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                       7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!WinExec                                                                                                                                                                                                                                                                      7C86158D 5 Bytes  JMP 00130464 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                             7C862C89 5 Bytes  JMP 00130608 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                              7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\WINDOWS\RTHDCPL.EXE[3212] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                              7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                  7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                              7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                  7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                  7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                    7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                  7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                              7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!CreateThread                                                                                                                                                                                                                                    7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                          7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                          7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!WinExec                                                                                                                                                                                                                                         7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                 7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                 7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] WS2_32.dll!socket                                                                                                                                                                                                                                            71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] WS2_32.dll!bind                                                                                                                                                                                                                                              71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[3248] WS2_32.dll!connect                                                                                                                                                                                                                                           71A9406A 5 Bytes  JMP 00130950 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                            7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                              7C801AD0 5 Bytes  JMP 00130090 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                          7C80220F 5 Bytes  JMP 00130694 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                              7C802332 5 Bytes  JMP 001302C0 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                              7C802367 5 Bytes  JMP 00130234 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                                7C809A61 5 Bytes  JMP 00130004 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                              7C809A82 5 Bytes  JMP 0013011C 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                          7C81043C 5 Bytes  JMP 001304F0 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!CreateThread                                                                                                                                                                                                                                                                7C810647 5 Bytes  JMP 0013057C 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                                      7C819527 5 Bytes  JMP 001303D8 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                                      7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!WinExec                                                                                                                                                                                                                                                                     7C86158D 5 Bytes  JMP 00130464 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                            7C862C89 5 Bytes  JMP 00130608 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                             7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\WINDOWS\AGRSMMSG.exe[3284] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                             7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                   7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                     7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                 7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                     7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                     7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                       7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                     7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                 7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!CreateThread                                                                                                                                                                                                                                                       7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                             7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                             7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!WinExec                                                                                                                                                                                                                                                            7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\SlickRun\sr.exe[3308] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                   7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\SlickRun\sr.exe[3308] user32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                    7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\SlickRun\sr.exe[3308] user32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                    7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Program Files\SlickRun\sr.exe[3308] WS2_32.dll!socket                                                                                                                                                                                                                                                               71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\SlickRun\sr.exe[3308] WS2_32.dll!bind                                                                                                                                                                                                                                                                 71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\SlickRun\sr.exe[3308] WS2_32.dll!connect                                                                                                                                                                                                                                                              71A9406A 5 Bytes  JMP 00130950 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                       7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                         7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                     7C80220F 5 Bytes  JMP 00130694 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                         7C802332 5 Bytes  JMP 001302C0 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                         7C802367 5 Bytes  JMP 00130234 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                           7C809A61 5 Bytes  JMP 00130004 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                         7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                     7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!CreateThread                                                                                                                                                                                                                                           7C810647 5 Bytes  JMP 0013057C 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                 7C819527 5 Bytes  JMP 001303D8 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                 7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!WinExec                                                                                                                                                                                                                                                7C86158D 5 Bytes  JMP 00130464 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                       7C862C89 5 Bytes  JMP 00130608 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] WS2_32.dll!socket                                                                                                                                                                                                                                                   71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] WS2_32.dll!bind                                                                                                                                                                                                                                                     71A93E00 5 Bytes  JMP 00130838 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] WS2_32.dll!connect                                                                                                                                                                                                                                                  71A9406A 5 Bytes  JMP 00130950 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                        7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Program Files\Rainlendar2\Rainlendar2.exe[3324] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                        7E3811D1 5 Bytes  JMP 00130720 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                                     7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                       7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                                   7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                       7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                       7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                         7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                       7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                                   7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!CreateThread                                                                                                                                                                                                                                                         7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                               7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                               7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!WinExec                                                                                                                                                                                                                                                              7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                                     7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                                      7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\ctfmon.exe[3368] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                                      7E3811D1 5 Bytes  JMP 00080720 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                               7C801A5D 5 Bytes  JMP 001301A8 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!VirtualProtect                                                                                                                                                                                                                 7C801AD0 5 Bytes  JMP 00130090 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                             7C80220F 5 Bytes  JMP 00130694 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!CreateProcessW                                                                                                                                                                                                                 7C802332 5 Bytes  JMP 001302C0 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!CreateProcessA                                                                                                                                                                                                                 7C802367 5 Bytes  JMP 00130234 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                   7C809A61 5 Bytes  JMP 00130004 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                 7C809A82 5 Bytes  JMP 0013011C 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                             7C81043C 5 Bytes  JMP 001304F0 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!CreateThread                                                                                                                                                                                                                   7C810647 5 Bytes  JMP 0013057C 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                         7C819527 5 Bytes  JMP 001303D8 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                         7C81DDE6 5 Bytes  JMP 0013034C 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!WinExec                                                                                                                                                                                                                        7C86158D 5 Bytes  JMP 00130464 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] kernel32.dll!SetThreadContext                                                                                                                                                                                                               7C862C89 5 Bytes  JMP 00130608 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                7E37DDB5 5 Bytes  JMP 001307AC 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                7E3811D1 5 Bytes  JMP 00130720 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WININET.dll!InternetConnectA                                                                                                                                                                                                                40C1DEAE 5 Bytes  JMP 00130F54 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WININET.dll!InternetConnectW                                                                                                                                                                                                                40C1F862 5 Bytes  JMP 00130FE0 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WININET.dll!InternetOpenA                                                                                                                                                                                                                   40C2D690 5 Bytes  JMP 00130D24 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WININET.dll!InternetOpenW                                                                                                                                                                                                                   40C2DB09 5 Bytes  JMP 00130DB0 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WININET.dll!InternetOpenUrlA                                                                                                                                                                                                                40C2F3A4 5 Bytes  JMP 00130E3C 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WININET.dll!InternetOpenUrlW                                                                                                                                                                                                                40C76DDF 5 Bytes  JMP 00130EC8 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WS2_32.dll!socket                                                                                                                                                                                                                           71A93B91 5 Bytes  JMP 001308C4 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WS2_32.dll!bind                                                                                                                                                                                                                             71A93E00 5 Bytes  JMP 00130838 
.text           C:\Documents and Settings\Carlos\Plocha\viry.cz\2\Gmer\gmer\gmer.exe[3764] WS2_32.dll!connect                                                                                                                                                                                                                          71A9406A 5 Bytes  JMP 00130950 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!VirtualProtectEx                                                                                                                                                                                                                                              7C801A5D 5 Bytes  JMP 000801A8 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!VirtualProtect                                                                                                                                                                                                                                                7C801AD0 5 Bytes  JMP 00080090 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!WriteProcessMemory                                                                                                                                                                                                                                            7C80220F 5 Bytes  JMP 00080694 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!CreateProcessW                                                                                                                                                                                                                                                7C802332 5 Bytes  JMP 000802C0 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!CreateProcessA                                                                                                                                                                                                                                                7C802367 5 Bytes  JMP 00080234 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!VirtualAlloc                                                                                                                                                                                                                                                  7C809A61 5 Bytes  JMP 00080004 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!VirtualAllocEx                                                                                                                                                                                                                                                7C809A82 5 Bytes  JMP 0008011C 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!CreateRemoteThread                                                                                                                                                                                                                                            7C81043C 5 Bytes  JMP 000804F0 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!CreateThread                                                                                                                                                                                                                                                  7C810647 5 Bytes  JMP 0008057C 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!CreateProcessInternalW                                                                                                                                                                                                                                        7C819527 5 Bytes  JMP 000803D8 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!CreateProcessInternalA                                                                                                                                                                                                                                        7C81DDE6 5 Bytes  JMP 0008034C 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!WinExec                                                                                                                                                                                                                                                       7C86158D 5 Bytes  JMP 00080464 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] kernel32.dll!SetThreadContext                                                                                                                                                                                                                                              7C862C89 5 Bytes  JMP 00080608 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] USER32.dll!SetWindowsHookExW                                                                                                                                                                                                                                               7E37DDB5 5 Bytes  JMP 000807AC 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] USER32.dll!SetWindowsHookExA                                                                                                                                                                                                                                               7E3811D1 5 Bytes  JMP 00080720 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] WS2_32.dll!socket                                                                                                                                                                                                                                                          71A93B91 5 Bytes  JMP 000808C4 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] WS2_32.dll!bind                                                                                                                                                                                                                                                            71A93E00 5 Bytes  JMP 00080838 
.text           C:\WINDOWS\system32\wbem\wmiapsrv.exe[3996] WS2_32.dll!connect                                                                                                                                                                                                                                                         71A9406A 5 Bytes  JMP 00080950 

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter]                                                                                                                                                                                                                                                      [AA6A4040] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter]                                                                                                                                                                                                                                                       [AA6A405B] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                                                                                                                                                                                  [AA6A40DF] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                                                                                                                                                                                               [AA6A4102] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                                                                                                                                                                                 [AA6A40DF] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter]                                                                                                                                                                                                                                                      [AA6A405B] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter]                                                                                                                                                                                                                                                     [AA6A4040] \SystemRoot\system32\drivers\fwdrv.sys (Kerio Technologies)

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                     [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                       [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                       [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                       [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                        [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                       [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                      [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                      [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                      [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT             C:\Program Files\a-squared Free\a2service.exe[1676] @ C:\WINDOWS\system32\crypt32.dll [KERNEL32.dll!CreateThread]                                                                                                                                                                                                      [004548B0] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                                                                                                                                                                                                 eamon.sys (Amon monitor/ESET)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                                                                                                                                                                                                                               fwdrv.sys (Kerio Technologies)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                                                                                                                                                                                                                               ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                                                                                                                                                                                                                              fwdrv.sys (Kerio Technologies)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                                                                                                                                                                                                                              ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                                                                                                                                                                                                                              fwdrv.sys (Kerio Technologies)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                                                                                                                                                                                                                              ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                                                                                                                                                                                                                            fwdrv.sys (Kerio Technologies)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                                                                                                                                                                                                                            ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                                                                                                                                                                                                                                               eamon.sys (Amon monitor/ESET)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                                                                                                                                                                                                                                               fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Threads - GMER 1.0.15 ----

Thread          System [4:424]                                                                                                                                                                                                                                                                                                         86686930

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                                                                                                                                                                                                                   
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                                                                                                                                                                                                                        C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                                                                                                                                                                                        0
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                                                                                                                                                                                                     0xE7 0xCD 0xCE 0x97 ...
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)                                                                                                                                                                                                          
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                                                                                                                                                                                                               0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                                                                                                                                                                                                                            0x09 0x98 0x2B 0xC0 ...
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)                                                                                                                                                                                                    
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                                                                                                                                                                                                                      0x55 0x1B 0x2A 0xE8 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                                                                                                                                                                                                       
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                                                                                                                                                                                    0
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                                                                                                                                                                                                 0x82 0x5B 0xF4 0x99 ...
Reg             HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                                                                                                                                                                                                                   
Reg             HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                                                                                                                                                                                        0
Reg             HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                                                                                                                                                                                                     0x82 0x5B 0xF4 0x99 ...

---- Files - GMER 1.0.15 ----

File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language                                           0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\generate.php                              22638 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php4                                      0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php4\.list                                10 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php4\basic.php                            625368 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5                                      0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\imap.php                             47307 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pcre.php                             14059 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\sockets.php                          33988 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\.list                                781 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\basic.php                            31083 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\bcmath.php                           4303 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\bz2.php                              4688 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\calendar.php                         8758 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\ctype.php                            3738 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\curl.php                             41314 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\date.php                             31030 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\dom.php                              46786 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\exif.php                             4461 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\fileinfo.php                         3346 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\filter.php                           12432 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\ftp.php                              19436 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\gd.php                               61090 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\gettext.php                          3189 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\gmp.php                              13124 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\hash.php                             6552 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\ibm_db2.php                          60385 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\iconv.php                            10987 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\json.php                             874 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\ldap.php                             26783 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\libxml.php                           4353 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mbstring.php                         32894 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mcrypt.php                           14069 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\memcache.php                         9150 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mhash.php                            3157 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mime_magic.php                       401 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\ming.php                             8638 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mssql.php                            15735 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mysql.php                            25019 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\mysqli.php                           21552 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\oci8.php                             53835 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\odbc.php                             26430 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\openssl.php                          25933 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pcntl.php                            10152 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\PDO.php                              6002 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pdo_ibm.php                          106 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pdo_mysql.php                        68 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\PDO_OCI.php                          64 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pdo_pgsql.php                        68 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pdo_sqlite.php                       70 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\pgsql.php                            62170 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\posix.php                            19380 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\Reflection.php                       13379 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\session.php                          9690 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\shmop.php                            2793 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\SimpleXML.php                        7588 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\soap.php                             11793 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\SPL.php                              44433 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\SQLite.php                           24139 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\standard.php                         299869 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\sybase_ct.php                        6314 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\sysvmsg.php                          8063 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\sysvsem.php                          1754 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\sysvshm.php                          2480 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\tidy.php                             11438 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\tokenizer.php                        4298 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\wddx.php                             2189 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\xml.php                              17427 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\xmlreader.php                        2299 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\xmlrpc.php                           4450 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\xmlwriter.php                        27113 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\xsl.php                              1670 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\Zend Data Cache.php                  373 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\Zend Debugger.php                    285 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\Zend Utils.php                       389 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\zend.php                             27604 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\zip.php                              15556 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\php5\zlib.php                             10388 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\language\README.txt                                580 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools                                        0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting                           0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\generetePhpLexer4.xml     321 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\generetePhpLexer5.xml     319 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\generetePHPTokenizer.xml  354 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\PhpLexer4.jflex           17384 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\PhpLexer5.jflex           19974 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\PHPTokenizer.jflex        72378 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\highlighting\skeleton.sse              9145 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\javacup                                0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\javacup\java-cup-10k.jar               83650 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\JFlex-1.2.2                            0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\JFlex-1.2.2\JFlex.jar                  115043 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\JFlex-1.4.1                            0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\JFlex-1.4.1\JFlex.jar                  175501 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser                                 0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\common                          0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4                            0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\ast_scanner.flex           23350 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\completion_scanner4.flex   28664 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\genereteAstParser.xml      652 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\genereteAstScanner.xml     319 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\generetePhpParser.xml      815 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\php_ast_parser.cup         63225 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php4\php_parser4.cup            37546 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5                            0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\ast_scanner.flex           28461 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\completion_scanner.flex    33544 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\genereteAstParser.xml      647 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\genereteAstScanner.xml     318 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\generetePhpParser.xml      814 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\php_ast_parser.cup         71826 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\php5\php_parser.cup             43940 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\phpdoc                          0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\phpdoc\documentor_scanner.flex  10440 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.core_2.0.0.v20081229-1135\Resources\parserTools\parser\phpdoc\genereteScanner.xml      336 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.debug.daemon_2.0.0.v20081229-1135\src.zip                                              8979 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php_feature.source_2.0.0.v20081229-1135\src\org.eclipse.php.server.core_2.0.0.v20081229-1135\src.zip                                               16567 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\dropins\eclipse\plugins\org.eclipse.php.core_2.0.0.v20081229-1135\org\eclipse\php\internal\core\documentModel\provisional\contenttype\ContentTypeIdForPHP.class                        687 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\ppc\Eclipse.app\Contents\Info.plist                                            1635 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\ppc\Eclipse.app\Contents\MacOS                                                 0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\ppc\Eclipse.app\Contents\MacOS\eclipse.ini                                     182 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\ppc\Eclipse.app\Contents\MacOS\launcher                                        59200 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\x86\Eclipse.app\Contents\Info.plist                                            1635 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\x86\Eclipse.app\Contents\MacOS                                                 0 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\x86\Eclipse.app\Contents\MacOS\eclipse.ini                                     182 bytes
File            C:\Documents and Settings\Carlos\Plocha\plocha 2009_12\prost - prtdit\=nutne protdit\pdt-all-in-one-win32-2.0.0GA\eclipse\features\org.eclipse.equinox.executable_3.3.101.R34x_v20081125-7H-ELfE8hXnkE15Wh9Tnyu\bin\carbon\macosx\x86\Eclipse.app\Contents\MacOS\launcher                                        59200 bytes

---- EOF - GMER 1.0.15 ----
