GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-01-30 05:24:45 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.8.16 Running: b5veueq0.exe; Driver: C:\DOCUME~1\Pete\LOCALS~1\Temp\pwdyapoc.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xED44BFC4] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xEDCE7510] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xED46F6A9] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xED44E456] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xED44E4AE] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xED44E5C4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xED46F05D] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xED44E3AC] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xED44E4FE] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xED44E400] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xED44E572] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xED44BFE8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xED46FD6F] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xED470025] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xED44E848] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xED46FBDA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xED46FA45] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xEDCE75C0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xED44BDB2] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xED44C00C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xED44E9BC] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xED44CAA4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xED44E486] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xED44E4D6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xED44E5EE] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xED46F3B9] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xED44E3D8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xED44E680] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xED44E53E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xED44E42E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xED44E764] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xED44E59C] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xEDCE7658] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xED46F8C0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xED44C96A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xED46F712] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xEDCEF9E6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xED46E6D0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xED44C030] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xED44C054] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xED44BE0C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xED44BF48] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xED46FE76] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xED44BF24] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xED44BF6C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xED44C078] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xEDCFB7A2] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_abnormal_termination + 140 804E27AC 4 Bytes CALL 943B6C70 .text ntoskrnl.exe!_abnormal_termination + 15C 804E27C8 4 Bytes [48, E8, 44, ED] .text ntoskrnl.exe!_abnormal_termination + 208 804E2874 8 Bytes [BC, E9, 44, ED, A4, CA, 44, ...] {MOV ESP, 0xa4ed44e9; RETF 0xed44} .text ntoskrnl.exe!_abnormal_termination + 271 804E28DD 3 Bytes [76, CE, ED] {JBE 0xffffffffffffffd0; IN EAX, DX} PAGE ntoskrnl.exe!ObInsertObject 805650BA 5 Bytes JMP EDCFA15C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 8056BB08 4 Bytes CALL ED44D00F \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) PAGE ntoskrnl.exe!ZwCreateProcessEx 8058124C 7 Bytes JMP EDCFB7A6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntoskrnl.exe!ObMakeTemporaryObject 805A038B 5 Bytes JMP EDCF869C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xF7C30F80] .text win32k.sys!EngSetLastError + 79A8 BF8242D4 5 Bytes JMP ED44EB9A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!FONTOBJ_pxoGetXform + C2CF BF85198B 5 Bytes JMP ED44EAD6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!XLATEOBJ_iXlate + 3581 BF85E514 5 Bytes JMP ED44EDE6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!XLATEOBJ_iXlate + 360C BF85E59F 5 Bytes JMP ED44EFBC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreatePalette + 88 BF85F812 5 Bytes JMP ED44EABE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngGetCurrentCodePage + 4128 BF873F30 5 Bytes JMP ED44EF76 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCopyBits + 4DEC BF89DBA0 5 Bytes JMP ED44EC0A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngEraseSurface + A9F7 BF8C2130 5 Bytes JMP ED44ECA4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngFillPath + 1517 BF8CA592 5 Bytes JMP ED44ED14 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngFillPath + 1797 BF8CA812 5 Bytes JMP ED44ED4E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngDeleteSemaphore + 3B3E BF8EC297 5 Bytes JMP ED44E9F2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreateClip + 19DF BF91348A 5 Bytes JMP ED44EB56 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreateClip + 25B3 BF91405E 5 Bytes JMP ED44EC6E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreateClip + 4F2C BF9169D7 5 Bytes JMP ED44F0D6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\LEXPPS.EXE[212] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\LEXPPS.EXE[212] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\LEXPPS.EXE[212] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\LEXPPS.EXE[212] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00381014 .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00380C0C .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380E10 .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\LEXPPS.EXE[212] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\LEXPPS.EXE[212] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\LEXPPS.EXE[212] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\LEXPPS.EXE[212] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\LEXPPS.EXE[212] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\LEXPPS.EXE[212] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC .text C:\Program Files\Java\jre6\bin\jqs.exe[336] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\Program Files\Java\jre6\bin\jqs.exe[336] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8 .text C:\Program Files\Java\jre6\bin\jqs.exe[336] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC .text C:\WINDOWS\system32\SearchIndexer.exe[404] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000D01F8 .text C:\WINDOWS\system32\SearchIndexer.exe[404] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\SearchIndexer.exe[404] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000D03FC .text C:\WINDOWS\system32\SearchIndexer.exe[404] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation) .text C:\WINDOWS\system32\SearchIndexer.exe[404] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00311014 .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00310804 .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00310A08 .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00310C0C .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00310E10 .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003101F8 .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003103FC .text C:\WINDOWS\system32\SearchIndexer.exe[404] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00310600 .text C:\WINDOWS\system32\SearchIndexer.exe[404] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00320804 .text C:\WINDOWS\system32\SearchIndexer.exe[404] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00320A08 .text C:\WINDOWS\system32\SearchIndexer.exe[404] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00320600 .text C:\WINDOWS\system32\SearchIndexer.exe[404] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003201F8 .text C:\WINDOWS\system32\SearchIndexer.exe[404] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003203FC .text C:\Program Files\AVAST Software\Avast\avastUI.exe[592] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\avastUI.exe[592] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\System32\smss.exe[604] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\csrss.exe[660] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\csrss.exe[660] KERNEL32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[684] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000701F8 .text C:\WINDOWS\system32\winlogon.exe[684] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[684] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000703FC .text C:\WINDOWS\system32\winlogon.exe[684] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\winlogon.exe[684] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\winlogon.exe[684] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\winlogon.exe[684] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\winlogon.exe[684] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\winlogon.exe[684] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\winlogon.exe[684] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\services.exe[728] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\services.exe[728] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\services.exe[728] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\services.exe[728] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\services.exe[728] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\services.exe[728] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\services.exe[728] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\services.exe[728] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\services.exe[728] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\services.exe[728] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\lsass.exe[748] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\lsass.exe[748] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\lsass.exe[748] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\lsass.exe[748] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\lsass.exe[748] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[908] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8 .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC .text C:\Program Files\Common Files\Motive\McciCMService.exe[936] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600 .text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[980] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\svchost.exe[980] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\svchost.exe[980] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\svchost.exe[980] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\svchost.exe[980] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\svchost.exe[980] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\svchost.exe[980] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\svchost.exe[1076] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1076] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1076] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1076] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\svchost.exe[1076] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\svchost.exe[1076] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\svchost.exe[1076] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\svchost.exe[1076] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\System32\svchost.exe[1104] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\System32\svchost.exe[1104] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1104] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\System32\svchost.exe[1104] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\System32\svchost.exe[1104] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\System32\svchost.exe[1104] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\System32\svchost.exe[1104] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\System32\svchost.exe[1104] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\System32\svchost.exe[1104] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\System32\svchost.exe[1104] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe[1248] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe[1248] KERNEL32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1272] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1272] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1272] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1272] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\svchost.exe[1272] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\svchost.exe[1272] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\svchost.exe[1272] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\svchost.exe[1272] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\svchost.exe[1272] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\svchost.exe[1272] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B0804 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0A08 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B0600 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B01F8 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1312] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B03FC .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\igfxsrvc.exe[1316] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\igfxsrvc.exe[1316] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\WINDOWS\system32\igfxsrvc.exe[1316] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\svchost.exe[1324] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1372] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\svchost.exe[1372] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\svchost.exe[1372] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\svchost.exe[1372] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\svchost.exe[1372] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\svchost.exe[1372] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\svchost.exe[1372] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1460] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1460] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1460] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[1932] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000A01F8 .text C:\WINDOWS\system32\ctfmon.exe[1932] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[1932] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000A03FC .text C:\WINDOWS\system32\ctfmon.exe[1932] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014 .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10 .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\ctfmon.exe[1932] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\ctfmon.exe[1932] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804 .text C:\WINDOWS\system32\ctfmon.exe[1932] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08 .text C:\WINDOWS\system32\ctfmon.exe[1932] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600 .text C:\WINDOWS\system32\ctfmon.exe[1932] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8 .text C:\WINDOWS\system32\ctfmon.exe[1932] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\LEXBCES.EXE[2004] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\LEXBCES.EXE[2004] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\WINDOWS\system32\LEXBCES.EXE[2004] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\spoolsv.exe[2028] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\spoolsv.exe[2028] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\spoolsv.exe[2028] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\spoolsv.exe[2028] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\system32\spoolsv.exe[2028] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\system32\spoolsv.exe[2028] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\system32\spoolsv.exe[2028] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\system32\spoolsv.exe[2028] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\system32\spoolsv.exe[2028] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\system32\spoolsv.exe[2028] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\System32\alg.exe[2528] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\System32\alg.exe[2528] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[2528] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\System32\alg.exe[2528] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[2528] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B0804 .text C:\WINDOWS\System32\alg.exe[2528] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0A08 .text C:\WINDOWS\System32\alg.exe[2528] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B0600 .text C:\WINDOWS\System32\alg.exe[2528] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B01F8 .text C:\WINDOWS\System32\alg.exe[2528] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B03FC .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014 .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804 .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08 .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10 .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8 .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC .text C:\WINDOWS\System32\alg.exe[2528] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600 .text C:\WINDOWS\Explorer.EXE[2712] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\Explorer.EXE[2712] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\Explorer.EXE[2712] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\Explorer.EXE[2712] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014 .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804 .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08 .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10 .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8 .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC .text C:\WINDOWS\Explorer.EXE[2712] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600 .text C:\WINDOWS\Explorer.EXE[2712] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804 .text C:\WINDOWS\Explorer.EXE[2712] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08 .text C:\WINDOWS\Explorer.EXE[2712] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600 .text C:\WINDOWS\Explorer.EXE[2712] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8 .text C:\WINDOWS\Explorer.EXE[2712] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003E1014 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003E0804 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003E0A08 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003E0C0C .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003E0E10 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003E01F8 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003E03FC .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003E0600 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003F0804 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003F0A08 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003F0600 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003F01F8 .text C:\Documents and Settings\Pete\Desktop\b5veueq0.exe[3124] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003F03FC .text C:\WINDOWS\System32\svchost.exe[3408] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8 .text C:\WINDOWS\System32\svchost.exe[3408] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[3408] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC .text C:\WINDOWS\System32\svchost.exe[3408] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014 .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804 .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08 .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10 .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8 .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC .text C:\WINDOWS\System32\svchost.exe[3408] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600 .text C:\WINDOWS\System32\svchost.exe[3408] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804 .text C:\WINDOWS\System32\svchost.exe[3408] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08 .text C:\WINDOWS\System32\svchost.exe[3408] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600 .text C:\WINDOWS\System32\svchost.exe[3408] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8 .text C:\WINDOWS\System32\svchost.exe[3408] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC .text C:\WINDOWS\system32\igfxpers.exe[3608] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\igfxpers.exe[3608] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\igfxpers.exe[3608] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\igfxpers.exe[3608] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\igfxpers.exe[3608] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\igfxpers.exe[3608] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\igfxpers.exe[3608] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\igfxpers.exe[3608] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\igfxpers.exe[3608] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\WINDOWS\system32\igfxpers.exe[3608] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\hkcmd.exe[3668] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\hkcmd.exe[3668] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\hkcmd.exe[3668] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\hkcmd.exe[3668] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\hkcmd.exe[3668] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\hkcmd.exe[3668] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\hkcmd.exe[3668] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\hkcmd.exe[3668] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\hkcmd.exe[3668] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\WINDOWS\system32\hkcmd.exe[3668] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\Program Files\HP\hpcoretech\hpcmpmgr.exe[3816] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe[3836] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\hphmon05.exe[3868] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\hphmon05.exe[3868] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\hphmon05.exe[3868] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\hphmon05.exe[3868] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00381014 .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00380C0C .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380E10 .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\hphmon05.exe[3868] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\hphmon05.exe[3868] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\hphmon05.exe[3868] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\hphmon05.exe[3868] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\hphmon05.exe[3868] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\hphmon05.exe[3868] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC .text C:\Program Files\Verizon\McciTrayApp.exe[3908] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\Verizon\McciTrayApp.exe[3908] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8 .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC .text C:\Program Files\Verizon\McciTrayApp.exe[3908] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003E1014 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003E0804 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003E0A08 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003E0C0C .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003E0E10 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003E01F8 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003E03FC .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003E0600 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003F0804 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003F0A08 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003F0600 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003F01F8 .text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3940] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003F03FC .text C:\WINDOWS\system32\HPZipm12.exe[3984] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\HPZipm12.exe[3984] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\HPZipm12.exe[3984] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\HPZipm12.exe[3984] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00381014 .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00380C0C .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380E10 .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\HPZipm12.exe[3984] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\HPZipm12.exe[3984] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\HPZipm12.exe[3984] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\HPZipm12.exe[3984] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600 .text C:\WINDOWS\system32\HPZipm12.exe[3984] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\HPZipm12.exe[3984] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62] .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62] .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC .text C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe[4000] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600 ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software) AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) Device \FileSystem\Fastfat \Fat B8DD9D20 AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software) ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 78108033 Disk \Device\Harddisk0\DR0 PE file @ sector 78108055 ---- EOF - GMER 1.0.15 ----