GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-04-09 13:07:24
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 TOSHIBA_MK6032GSX rev.AS311G
Running: gmer.exe; Driver: C:\DOCUME~1\Pietro\LOCALS~1\Temp\ufryifow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xF2318DF8]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwAdjustPrivilegesToken [0xEEEC8690]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xF23CDA5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0xF231985E]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwClose [0xEEEC8F94]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwConnectPort [0xEEEC9DC8]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateEvent [0xEEECA312]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xF231E330]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateFile [0xEEEC9270]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xF231E422]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateKey [0xEEEC7500]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateMutant [0xEEECA1F8]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateNamedPipeFile [0xEEEC827E]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreatePort [0xEEECA0CC]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateSection [0xEEEC8426]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateSemaphore [0xEEECA432]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateThread [0xEEEC8C1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xF231E3DC]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwCreateWaitablePort [0xEEECA162]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwDebugActiveProcess [0xEEECBB1A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xF2318E44]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwDeleteKey [0xEEEC7B0A]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwDeleteValueKey [0xEEEC7EBE]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwDeviceIoControlFile [0xEEEC96F2]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwDuplicateObject [0xEEECCD26]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwEnumerateKey [0xEEEC800A]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwEnumerateValueKey [0xEEEC80A2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xF23CDB34]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwFsControlFile [0xEEEC9500]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwLoadDriver [0xEEECBC0C]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwLoadKey [0xEEEC74DC]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwLoadKey2 [0xEEEC74EE]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwMapViewOfSection [0xEEECC374]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xF2318E90]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwNotifyChangeKey [0xEEEC81CE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xF2319B02]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenEvent [0xEEECA3A8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xF231E352]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenFile [0xEEEC9016]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xF231E446]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenKey [0xEEEC76C0]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenMutant [0xEEECA288]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenProcess [0xEEEC88CC]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenSection [0xEEECC10E]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenSemaphore [0xEEECA4C8]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwOpenThread [0xEEEC87BE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xF231E400]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xF23CDCA0]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwQueryKey [0xEEEC813A]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwQueryMultipleValueKey [0xEEEC7D72]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xF23199CE]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwQuerySection [0xEEECC6AE]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwQueryValueKey [0xEEEC799C]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwQueueApcThread [0xEEECBFA0]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwRenameKey [0xEEEC7C2C]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwReplaceKey [0xEEEC6F16]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwReplyPort [0xEEECA82C]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwReplyWaitReceivePort [0xEEECA6F2]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwRequestWaitReplyPort [0xEEECB8B4]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwRestoreKey [0xEEEC728E]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwResumeThread [0xEEECCBC8]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSaveKey [0xEEEC6EAE]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSecureConnectPort [0xEEEC9B0E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xF2318EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xF2318F28]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSetContextThread [0xEEEC8E38]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSetInformationToken [0xEEECB154]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSetSecurityObject [0xEEECBDAA]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSetSystemInformation [0xEEECC7FE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xF2318CEA]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSetValueKey [0xEEEC7816]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xF2318C92]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSuspendProcess [0xEEECC8F0]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSuspendThread [0xEEECCA2A]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwSystemDebugControl [0xEEECBA3E]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwTerminateProcess [0xEEEC8A68]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwTerminateThread [0xEEEC89C8]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwUnmapViewOfSection [0xEEECC552]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xF2318F74]
SSDT \SystemRoot\system32\DRIVERS\7228290drv.sys ZwWriteVirtualMemory [0xEEEC8B52]
INT 0x63 ? 8576EBF8
INT 0x82 ? 8576BBF8
INT 0x83 ? 8576BBF8
INT 0x83 ? 8576BBF8
INT 0xA4 ? 85208F00
INT 0xA4 ? 85208F00
INT 0xA4 ? 85208F00
INT 0xA4 ? 85208F00
Code \SystemRoot\system32\DRIVERS\7228290drv.sys FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\7228290drv.sys IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + D8 804E2734 16 Bytes [12, A3, EC, EE, 30, E3, 31, ...] {ADC AH, [EBX-0x1ccf1114]; XOR EDX, ESI; JO 0xffffffffffffff9c; IN AL, DX ; OUT DX, AL ; AND AH, AH; XOR EDX, ESI}
.text ntoskrnl.exe!_abnormal_termination + 1D0 804E282C 12 Bytes [0C, BC, EC, EE, DC, 74, EC, ...] {OR AL, 0xbc; IN AL, DX ; OUT DX, AL ; FDIV QWORD [ESP+EBP*8-0x12]; OUT DX, AL ; JZ 0xfffffffffffffff7; OUT DX, AL }
.text ntoskrnl.exe!_abnormal_termination + 214 804E2870 16 Bytes [A8, A3, EC, EE, 52, E3, 31, ...]
.text ntoskrnl.exe!_abnormal_termination + 34C 804E29A8 16 Bytes [2C, 7C, EC, EE, 16, 6F, EC, ...] {SUB AL, 0x7c; IN AL, DX ; OUT DX, AL ; PUSH SS; OUTSD ; IN AL, DX ; OUT DX, AL ; SUB AL, 0xa8; IN AL, DX ; OUT DX, AL ; REPNZ CMPSB ; IN AL, DX ; OUT DX, AL }
.text ntoskrnl.exe!_abnormal_termination + 394 804E29F0 16 Bytes [0E, 9B, EC, EE, DC, 8E, 31, ...]
.text ...
.text ntoskrnl.exe!IoIsOperationSynchronous 804E875A 5 Bytes JMP EEEBB3AC \SystemRoot\system32\DRIVERS\7228290drv.sys
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 80512919 5 Bytes JMP EEEBAFD0 \SystemRoot\system32\DRIVERS\7228290drv.sys
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 8056B8A2 4 Bytes CALL F231A19F \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? spus.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload F6C7F8EC 5 Bytes JMP 852084E0
.text a7wtm41m.SYS F6BD0386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a7wtm41m.SYS F6BD03AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a7wtm41m.SYS F6BD03C4 3 Bytes [00, 80, 02]
.text a7wtm41m.SYS F6BD03C9 1 Byte [30]
.text a7wtm41m.SYS F6BD03C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text win32k.sys!EngFreeUserMem + 674 BF8098BF 5 Bytes JMP F231D180 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFreeUserMem + 35D0 BF80C81B 5 Bytes JMP F231D07C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSurface + 45 BF8138AE 5 Bytes JMP F231D036 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!BRUSHOBJ_pvAllocRbrush + 322E BF81E72F 5 Bytes JMP F231BE66 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 199A BF820E29 5 Bytes JMP F231C724 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngSetLastError + 77C8 BF8287B9 5 Bytes JMP F231BF84 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + 698 BF838479 5 Bytes JMP F231D2EA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + 3219 BF83AFFA 5 Bytes JMP F231D4F2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + D4C7 BF8452A8 5 Bytes JMP F231CF3C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + DDB0 BF845B91 5 Bytes JMP F231BFF4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + 11969 BF84974A 5 Bytes JMP F231C70C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 35A0 BF8648EA 5 Bytes JMP F231C384 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 362B BF864975 5 Bytes JMP F231C562 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 35C1 BF8688DD 5 Bytes JMP F231D0BA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 3FE9 BF869305 5 Bytes JMP F231C7E6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 40A9 BF8693C5 5 Bytes JMP F231BE4E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetCurrentCodePage + 411E BF886D9A 5 Bytes JMP F231C51C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetLastError + 1606 BF8A4009 5 Bytes JMP F231C7FE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 3AA1 BF8A8967 5 Bytes JMP F231D232 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + 4616 BF8AD4D2 5 Bytes JMP F231D450 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngAlphaBlend + 3E8 BF8C30F9 5 Bytes JMP F231C104 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_vGetBounds + 51A8 BF8EDB23 5 Bytes JMP F231C1AC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_vGetBounds + 5428 BF8EDDA3 5 Bytes JMP F231C2E4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_vGetBounds + 764E BF8EFFC9 5 Bytes JMP F231BD52 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_vGetBounds + EF2B BF8F78A6 5 Bytes JMP F231C73C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 19C1 BF9131E9 1 Byte [E9]
.text win32k.sys!EngCreateClip + 19C1 BF9131E9 5 Bytes JMP F231BF22 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 2595 BF913DBD 5 Bytes JMP F231C0B0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 4EF4 BF91671C 5 Bytes JMP F231C67C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 1940 BF944774 5 Bytes JMP F231D3A8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? system32\DRIVERS\7228290drv.sys Systém nemůže nalézt uvedenou cestu. !
? system32\DRIVERS\51032920.sys Systém nemůže nalézt uvedenou cestu. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 001401F8
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 001403FC
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D0804
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0A08
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D0600
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D01F8
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D03FC
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 003E1014
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 003E0804
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 003E0A08
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 003E0C0C
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 003E0E10
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003E01F8
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003E03FC
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[416] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 003E0600
.text C:\WINDOWS\RTHDCPL.EXE[436] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 001401F8
.text C:\WINDOWS\RTHDCPL.EXE[436] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\RTHDCPL.EXE[436] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 001403FC
.text C:\WINDOWS\RTHDCPL.EXE[436] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\RTHDCPL.EXE[436] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D0804
.text C:\WINDOWS\RTHDCPL.EXE[436] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0A08
.text C:\WINDOWS\RTHDCPL.EXE[436] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D0600
.text C:\WINDOWS\RTHDCPL.EXE[436] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D01F8
.text C:\WINDOWS\RTHDCPL.EXE[436] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D03FC
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 003E1014
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 003E0804
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 003E0A08
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 003E0C0C
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 003E0E10
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003E01F8
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003E03FC
.text C:\WINDOWS\RTHDCPL.EXE[436] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 003E0600
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 001401F8
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 001403FC
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D0804
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0A08
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D0600
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D01F8
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D03FC
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 003E1014
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 003E0804
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 003E0A08
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 003E0C0C
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 003E0E10
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003E01F8
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003E03FC
.text C:\Program Files\HSPA USB MODEM\ModemListener.exe[452] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 003E0600
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 001501F8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 001503FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E0804
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0A08
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E0600
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E01F8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E03FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 003F1014
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 003F0804
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 003F0A08
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 003F0C0C
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 003F0E10
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003F01F8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003F03FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[456] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 003F0600
.text C:\Program Files\AVAST Software\Avast\avastUI.exe[524] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\avastUI.exe[524] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\System32\smss.exe[532] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000A01F8
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000A03FC
.text C:\WINDOWS\system32\ctfmon.exe[552] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00381014
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00380804
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00380A08
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00380C0C
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00380E10
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003801F8
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003803FC
.text C:\WINDOWS\system32\ctfmon.exe[552] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00380600
.text C:\WINDOWS\system32\ctfmon.exe[552] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00390804
.text C:\WINDOWS\system32\ctfmon.exe[552] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00390A08
.text C:\WINDOWS\system32\ctfmon.exe[552] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00390600
.text C:\WINDOWS\system32\ctfmon.exe[552] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003901F8
.text C:\WINDOWS\system32\ctfmon.exe[552] USER32.dll!UnhookWinEvent 7E3818AC 3 Bytes JMP 003903FC
.text C:\WINDOWS\system32\ctfmon.exe[552] USER32.dll!UnhookWinEvent + 4 7E3818B0 1 Byte [82]
.text C:\WINDOWS\system32\csrss.exe[604] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\csrss.exe[604] KERNEL32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[660] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000701F8
.text C:\WINDOWS\system32\winlogon.exe[660] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[660] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000703FC
.text C:\WINDOWS\system32\winlogon.exe[660] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\winlogon.exe[660] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\winlogon.exe[660] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\winlogon.exe[660] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\system32\winlogon.exe[660] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\system32\winlogon.exe[660] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\system32\winlogon.exe[660] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[716] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\services.exe[716] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\services.exe[716] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\services.exe[716] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\services.exe[716] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\system32\services.exe[716] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\system32\services.exe[716] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\system32\services.exe[716] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[728] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\lsass.exe[728] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\lsass.exe[728] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\lsass.exe[728] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\lsass.exe[728] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\system32\lsass.exe[728] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\system32\lsass.exe[728] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\system32\lsass.exe[728] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00321014
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00320804
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00320A08
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00320C0C
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00320E10
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003201F8
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003203FC
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00320600
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00330804
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00330A08
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00330600
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003301F8
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[800] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003303FC
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 001401F8
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 001403FC
.text C:\WINDOWS\system32\Ati2evxx.exe[892] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[892] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D0804
.text C:\WINDOWS\system32\Ati2evxx.exe[892] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0A08
.text C:\WINDOWS\system32\Ati2evxx.exe[892] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D0600
.text C:\WINDOWS\system32\Ati2evxx.exe[892] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D01F8
.text C:\WINDOWS\system32\Ati2evxx.exe[892] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D03FC
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 003E1014
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 003E0804
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 003E0A08
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 003E0C0C
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 003E0E10
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003E01F8
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003E03FC
.text C:\WINDOWS\system32\Ati2evxx.exe[892] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 003E0600
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1056] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\System32\svchost.exe[1056] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\System32\svchost.exe[1056] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\System32\svchost.exe[1056] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\System32\svchost.exe[1056] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\System32\svchost.exe[1056] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\System32\svchost.exe[1056] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\System32\svchost.exe[1056] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 00310600
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003101F8
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003103FC
.text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916ADA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!GetBinaryTypeW + 80 7C86936C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 00301014
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 00300804
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 00300A08
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 00300C0C
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 00300E10
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 003001F8
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 003003FC
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 00300600
.text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00310804
.text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310A08