Pretzelogic
Topic Starter
Hello. I've just discovered this website - it looks like an amazing online resource, and I hope somebody here will be able to help me (considering I'm barely beyond the "novice" stage - if that). First: here are a few basics about my system:
Manuf/Model: Dell Inspiron 530
Processor: Intel Core2 Quad CPU Q6600 @ 2.40GHz
RAM: 3.00 GB
OS: Win Vista Home Ultimate SP2 (32-bit)
Sometime back (maybe six months ago or so?) I seem to have picked up, without realizing it, some sort of add-on for IE8, while trying out some other software (which I didn't even decide to keep). I had opted not to take the add-on when it looked like it was trying to be installed, and when I uninstalled the other software, I thought (incorrectly) that it had removed everything it should have.
Recently, I thought I noticed that web pages were loading more slowly, and I got a couple of pop-up error messages that IE8 had stopped working and would need to be closed (even though that did not appear to be the case), and I was able to merely escape out of the "error messages". Windows also recently popped up with a "Problem Report and Solution" suggesting that issues with IE8 might be caused by add-ons. In taking a fresh look at what add-ons were installed, I noticed the pesky item that I thought had been removed was still listed (though it was shown as "disabled"). I tried to remove it, using the Program Uninstall feature from the Control Panel, and it disappeared from the IE8 menu.
At this point however, I discovered that there were still a folder and subfolder left behind on my C: drive, under the Program Files folder. I still wasn't unduly alarmed by that (it doesn't seem to be TOO unusual for an uninstll routine to leave behind a few stray files or folders). So, after navigating in Windows Explorer to the folder Program Files/SkymediaPack (and its subfolder "SkyToolbar"), I tried to "permanently" delete it. At that point, I saw the following series of prompts:
"Are you sure you want to permanently delete this folder? Yes/No"
Selecting "Yes" brought up:
"You need to confirm this operation. Continue/Skip/Cancel"
Selecting "Continue" brought up a UAC dialog:
"Windows needs your permission to continue. If you started this action, continue. File Operation Microsoft Windows
{3AD05575-8857-4850-9277-11B85BDI
Continue/Cancel"
Selecting "Continue" brought up this alarming prompt:
"Destination Folder Access Denied
You need permission to perform this action
SkyToolbar
Date created 5/19/2009 10:40 PM
Try Again/Skip/Cancel"
Selecting "Try Again" appears to result in and endless loop in which that same prompt just keeps re-appearing. Selecting "Skip" or "Cancel" has just the effect they would suggest - leaving the folders in place. And sure enough, now, when I try to open the SkyToolbar subfolder in Windows Explorer, I get a pop-up announcing "Location is not available. C:\Program Files\SkyMediaPack\SkyToolbar is not accessible. Access is Denied." The only option offered is "OK". I *WAS* able to look at the contents before, but of course, now I can't remember what it contained (one file, two? file name?).
Trying to follow the instructions in the "Are You Infected" topic, I ran ATF-Cleaner. I selected all and emptied them (though the pre-fetch choice was "disabled" - was that intended, or an anomaly?).
I ran SystemRestorePoint.exe successfully. Q: (just out of sheer curiosity) Is there a specific reason why it was necessary to download and run a special utility for this, instead of simply creating a restore point with the system's Backup/Restore function in the Control Panel?
ERUNT seemed to run successfully, so I should have a proper backup of the registry.
I downloaded MBAM; it sucessfully updated from V3510 to V3811. When run, it reported finding 6 items infected - 4 registry keys & 2 folders, all of which appeared to be related to that annoying SkyMedia stuff. After trying to remove the "selected" items, it reported that the 2 folders needed to be deleted on reboot; so I rebooted, and they appear to be gone (yay!). At this point, you folks are already my heroes.
I then downloaded GMER. At first, it seemed to be running OK, but then it seemed to get hung up while scanning something called: \device\HarddiskVolumeShadowCopy20. After more than 5 hours spent scanning that one item, I decided that it must have run into a problem, and hit the "STOP" button. I saved what there was into a logfile. The instructions in "Are You Infected" said DeFogger should be run "If GMER doesn't start". At risk of interpreting this too literally, I decided that, since GMER did start (it just didn't finish), I should hold off on DeFogger unless specifically instructed to use it by one of your experts.
Finally, I downloaded and ran DDS. For now, it looks like MBAM was enough, by itself, to deal with the specific item that first led me here. But now, after GMER failed to give me an all-clear, I have the heebie-jeebies thinking I may have something even more insidious quietly festering in my system. I look forward to your assistance in straightening this out; and thank you in advance for any additional assistance you may be able to provide. Here are the logfiles that "Are You Infected" requested that I post:
—– MBAM logfile —–
Malwarebytes' Anti-Malware 1.44
Database version: 3811
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
3/1/2010 8:57:15 PM
mbam-log-2010-03-01 (20-57-15).txt
Scan type: Quick Scan
Objects scanned: 128876
Time elapsed: 7 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f334c7b0-8774-4d5b-bd7a-4f448d03a1ae} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2863e737-dd3f-4280-9af8-e9e79c16f312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{f334c7b0-8774-4d5b-bd7a-4f448d03a1ae} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2863e737-dd3f-4280-9af8-e9e79c16f312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\SkyMediaPack (Adware.SkyMediaPack) -> Delete on reboot.
C:\Program Files\SkyMediaPack\SkyToolbar (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
Files Infected:
(No malicious items detected)
—– GMER logfile (partial?)—–
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-02 02:48:17
Windows 6.0.6002 Service Pack 2
Running: v2xpwv9v.exe; Driver: C:\Users\LeeAd\AppData\Local\Temp\fxtdipow.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x8A411CDE]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x8A411ED0]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x8A411984]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8A4120D8]
Code 716FFFFB NtTestAlert
Code 716FFFFB ZwTestAlert
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 209 822E194C 8 Bytes [DE, 1C, 41, 8A, D0, 1E, 41, …]
.text ntkrnlpa.exe!KeSetEvent + 621 822E1D64 4 Bytes [84, 19, 41, 8A]
.text ntkrnlpa.exe!KeSetEvent + 6E5 822E1E28 4 Bytes [D8, 20, 41, 8A]
? System32\drivers\gmfdtth.sys The system cannot find the path specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\smss.exe[448] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[512] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[596] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[608] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[644] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[672] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[704] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\ico.exe[784] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[876] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SLsvc.exe[1432] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1916] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2124] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] kernel32.dll!CreateThread + 1A 7569C928 4 Bytes CALL 0044BC05 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2460] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[2700] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3016] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3556] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3556] kernel32.dll!CreateThread + 1A 7569C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[3896] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3940] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3948] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\Explorer.EXE[4004] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3556] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73D27817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73D7A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73D2BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73D1F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73D275E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73D1E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73D58395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73D2DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73D1FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73D1FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73D171CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73DACAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73D4C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73D1D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73D16853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73D1687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73D22AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
—– DDS logfiles —–
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 3:52:28.18 on Tue 03/02/2010
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3069.1759 [GMT -5:00]
AV: PC-cillin Internet Security - Virus Protection *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
SP: PC-cillin Internet Security - Spyware Protection *enabled* (Updated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *enabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Secura Backup\securasvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Windows\System32\ico.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\WinAmp\winampa.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe
C:\Windows\System32\Pmxmiced.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\mobsync.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\LeeAd\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uWindow Title = Internet Explorer provided by Dell
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\programdata\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\leead\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: []
mRun: [WrtMon.exe] c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SBCSTray] c:\program files\sunbelt software\counterspy\SBCSTray.exe
mRun: [PMX Daemon] ICO.EXE
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [PKWARE Certificate Proxy Client] c:\progra~1\pkware\pkzipw\pkpcsr.exe
mRun: [SBRegRebootCleaner] c:\program files\sunbelt software\counterspy\SBRC.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [Google Updater] "c:\program files\google\google updater\GoogleUpdater.exe" -systray -startup
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
dRun: [CtxfiReg] CTXFIREG.exe /FAIL2
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\boincm~1.lnk - c:\program files\boinc\boincmgr.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secure~1.lnk - c:\program files\pkware\pkzipm\12.10.0012\PKTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programdata\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-12-29 207792]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-9-11 124832]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-5-6 36368]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-7-13 198168]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-2-19 1353240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-7-13 73752]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-6 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-6 19008]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-5-6 280392]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-7-13 198168]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-2-19 1353240]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-7-13 73752]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-11 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-5-6 30192]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2009-2-19 1222680]
S3 HSXHWCD2;HSXHWCD2;c:\windows\system32\drivers\HSXHWCD2.sys [2008-6-10 243712]
=============== Created Last 30 ================
2010-03-01 20:45 –d—– c:\users\leead\appdata\roaming\Malwarebytes
2010-03-01 20:45 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-01 20:44 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-01 20:44 –d—– c:\programdata\Malwarebytes
2010-03-01 20:44 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-01 20:44 –d—– c:\progra~2\Malwarebytes
2010-02-23 17:11 –d—– C:\JAM Software
2010-02-12 20:50 21,163,478 a——- c:\windows\system32\SBSP.dat
2010-02-04 01:33 –d—– c:\windows\system32\appmgmt
==================== Find3M ====================
2010-02-16 21:36 143,360 a——- c:\windows\inf\infstrng.dat
2010-02-16 21:36 51,200 a——- c:\windows\inf\infpub.dat
2009-12-10 21:31 665,600 a——- c:\windows\inf\drvindex.dat
2009-12-10 21:31 143,360 a——- c:\windows\inf\infstor.dat
2008-07-18 22:08 174 a–sh— c:\program files\desktop.ini
2008-06-12 23:06 61,224 ——– c:\users\leead\GoToAssistDownloadHelper.exe
2006-11-02 07:40 287,440 ——– c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:40 287,440 ——– c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:40 30,674 ——– c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:40 30,674 ——– c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 ——– c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 ——– c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 ——– c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 ——– c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 3:54:14.48 ===============
"attach.txt" is attached in the file "attach_txt.zip"
Thanks again!
Manuf/Model: Dell Inspiron 530
Processor: Intel Core2 Quad CPU Q6600 @ 2.40GHz
RAM: 3.00 GB
OS: Win Vista Home Ultimate SP2 (32-bit)
Sometime back (maybe six months ago or so?) I seem to have picked up, without realizing it, some sort of add-on for IE8, while trying out some other software (which I didn't even decide to keep). I had opted not to take the add-on when it looked like it was trying to be installed, and when I uninstalled the other software, I thought (incorrectly) that it had removed everything it should have.
Recently, I thought I noticed that web pages were loading more slowly, and I got a couple of pop-up error messages that IE8 had stopped working and would need to be closed (even though that did not appear to be the case), and I was able to merely escape out of the "error messages". Windows also recently popped up with a "Problem Report and Solution" suggesting that issues with IE8 might be caused by add-ons. In taking a fresh look at what add-ons were installed, I noticed the pesky item that I thought had been removed was still listed (though it was shown as "disabled"). I tried to remove it, using the Program Uninstall feature from the Control Panel, and it disappeared from the IE8 menu.
At this point however, I discovered that there were still a folder and subfolder left behind on my C: drive, under the Program Files folder. I still wasn't unduly alarmed by that (it doesn't seem to be TOO unusual for an uninstll routine to leave behind a few stray files or folders). So, after navigating in Windows Explorer to the folder Program Files/SkymediaPack (and its subfolder "SkyToolbar"), I tried to "permanently" delete it. At that point, I saw the following series of prompts:
"Are you sure you want to permanently delete this folder? Yes/No"
Selecting "Yes" brought up:
"You need to confirm this operation. Continue/Skip/Cancel"
Selecting "Continue" brought up a UAC dialog:
"Windows needs your permission to continue. If you started this action, continue. File Operation Microsoft Windows
{3AD05575-8857-4850-9277-11B85BDI
Continue/Cancel"
Selecting "Continue" brought up this alarming prompt:
"Destination Folder Access Denied
You need permission to perform this action
SkyToolbar
Date created 5/19/2009 10:40 PM
Try Again/Skip/Cancel"
Selecting "Try Again" appears to result in and endless loop in which that same prompt just keeps re-appearing. Selecting "Skip" or "Cancel" has just the effect they would suggest - leaving the folders in place. And sure enough, now, when I try to open the SkyToolbar subfolder in Windows Explorer, I get a pop-up announcing "Location is not available. C:\Program Files\SkyMediaPack\SkyToolbar is not accessible. Access is Denied." The only option offered is "OK". I *WAS* able to look at the contents before, but of course, now I can't remember what it contained (one file, two? file name?).
Trying to follow the instructions in the "Are You Infected" topic, I ran ATF-Cleaner. I selected all and emptied them (though the pre-fetch choice was "disabled" - was that intended, or an anomaly?).
I ran SystemRestorePoint.exe successfully. Q: (just out of sheer curiosity) Is there a specific reason why it was necessary to download and run a special utility for this, instead of simply creating a restore point with the system's Backup/Restore function in the Control Panel?
ERUNT seemed to run successfully, so I should have a proper backup of the registry.
I downloaded MBAM; it sucessfully updated from V3510 to V3811. When run, it reported finding 6 items infected - 4 registry keys & 2 folders, all of which appeared to be related to that annoying SkyMedia stuff. After trying to remove the "selected" items, it reported that the 2 folders needed to be deleted on reboot; so I rebooted, and they appear to be gone (yay!). At this point, you folks are already my heroes.
I then downloaded GMER. At first, it seemed to be running OK, but then it seemed to get hung up while scanning something called: \device\HarddiskVolumeShadowCopy20. After more than 5 hours spent scanning that one item, I decided that it must have run into a problem, and hit the "STOP" button. I saved what there was into a logfile. The instructions in "Are You Infected" said DeFogger should be run "If GMER doesn't start". At risk of interpreting this too literally, I decided that, since GMER did start (it just didn't finish), I should hold off on DeFogger unless specifically instructed to use it by one of your experts.
Finally, I downloaded and ran DDS. For now, it looks like MBAM was enough, by itself, to deal with the specific item that first led me here. But now, after GMER failed to give me an all-clear, I have the heebie-jeebies thinking I may have something even more insidious quietly festering in my system. I look forward to your assistance in straightening this out; and thank you in advance for any additional assistance you may be able to provide. Here are the logfiles that "Are You Infected" requested that I post:
—– MBAM logfile —–
Malwarebytes' Anti-Malware 1.44
Database version: 3811
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
3/1/2010 8:57:15 PM
mbam-log-2010-03-01 (20-57-15).txt
Scan type: Quick Scan
Objects scanned: 128876
Time elapsed: 7 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f334c7b0-8774-4d5b-bd7a-4f448d03a1ae} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2863e737-dd3f-4280-9af8-e9e79c16f312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{f334c7b0-8774-4d5b-bd7a-4f448d03a1ae} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2863e737-dd3f-4280-9af8-e9e79c16f312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\SkyMediaPack (Adware.SkyMediaPack) -> Delete on reboot.
C:\Program Files\SkyMediaPack\SkyToolbar (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
Files Infected:
(No malicious items detected)
—– GMER logfile (partial?)—–
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-02 02:48:17
Windows 6.0.6002 Service Pack 2
Running: v2xpwv9v.exe; Driver: C:\Users\LeeAd\AppData\Local\Temp\fxtdipow.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x8A411CDE]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x8A411ED0]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x8A411984]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8A4120D8]
Code 716FFFFB NtTestAlert
Code 716FFFFB ZwTestAlert
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 209 822E194C 8 Bytes [DE, 1C, 41, 8A, D0, 1E, 41, …]
.text ntkrnlpa.exe!KeSetEvent + 621 822E1D64 4 Bytes [84, 19, 41, 8A]
.text ntkrnlpa.exe!KeSetEvent + 6E5 822E1E28 4 Bytes [D8, 20, 41, 8A]
? System32\drivers\gmfdtth.sys The system cannot find the path specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\smss.exe[448] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[512] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[596] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[608] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[644] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[672] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[704] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\ico.exe[784] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[876] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SLsvc.exe[1432] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1916] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2124] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] kernel32.dll!CreateThread + 1A 7569C928 4 Bytes CALL 0044BC05 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2460] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[2700] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3016] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3556] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3556] kernel32.dll!CreateThread + 1A 7569C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[3896] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3940] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3948] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\Explorer.EXE[4004] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3556] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73D27817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73D7A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73D2BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73D1F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73D275E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73D1E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73D58395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73D2DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73D1FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73D1FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73D171CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73DACAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73D4C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73D1D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73D16853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73D1687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73D22AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
—– DDS logfiles —–
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 3:52:28.18 on Tue 03/02/2010
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3069.1759 [GMT -5:00]
AV: PC-cillin Internet Security - Virus Protection *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
SP: PC-cillin Internet Security - Spyware Protection *enabled* (Updated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *enabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Secura Backup\securasvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Windows\System32\ico.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\WinAmp\winampa.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe
C:\Windows\System32\Pmxmiced.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\mobsync.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\LeeAd\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uWindow Title = Internet Explorer provided by Dell
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\programdata\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\leead\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: []
mRun: [WrtMon.exe] c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SBCSTray] c:\program files\sunbelt software\counterspy\SBCSTray.exe
mRun: [PMX Daemon] ICO.EXE
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [PKWARE Certificate Proxy Client] c:\progra~1\pkware\pkzipw\pkpcsr.exe
mRun: [SBRegRebootCleaner] c:\program files\sunbelt software\counterspy\SBRC.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [Google Updater] "c:\program files\google\google updater\GoogleUpdater.exe" -systray -startup
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
dRun: [CtxfiReg] CTXFIREG.exe /FAIL2
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\boincm~1.lnk - c:\program files\boinc\boincmgr.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secure~1.lnk - c:\program files\pkware\pkzipm\12.10.0012\PKTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programdata\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-12-29 207792]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-9-11 124832]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-5-6 36368]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-7-13 198168]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-2-19 1353240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-7-13 73752]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-6 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-6 19008]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-5-6 280392]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-7-13 198168]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-2-19 1353240]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-7-13 73752]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-11 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-5-6 30192]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2009-2-19 1222680]
S3 HSXHWCD2;HSXHWCD2;c:\windows\system32\drivers\HSXHWCD2.sys [2008-6-10 243712]
=============== Created Last 30 ================
2010-03-01 20:45 –d—– c:\users\leead\appdata\roaming\Malwarebytes
2010-03-01 20:45 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-01 20:44 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-01 20:44 –d—– c:\programdata\Malwarebytes
2010-03-01 20:44 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-01 20:44 –d—– c:\progra~2\Malwarebytes
2010-02-23 17:11 –d—– C:\JAM Software
2010-02-12 20:50 21,163,478 a——- c:\windows\system32\SBSP.dat
2010-02-04 01:33 –d—– c:\windows\system32\appmgmt
==================== Find3M ====================
2010-02-16 21:36 143,360 a——- c:\windows\inf\infstrng.dat
2010-02-16 21:36 51,200 a——- c:\windows\inf\infpub.dat
2009-12-10 21:31 665,600 a——- c:\windows\inf\drvindex.dat
2009-12-10 21:31 143,360 a——- c:\windows\inf\infstor.dat
2008-07-18 22:08 174 a–sh— c:\program files\desktop.ini
2008-06-12 23:06 61,224 ——– c:\users\leead\GoToAssistDownloadHelper.exe
2006-11-02 07:40 287,440 ——– c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:40 287,440 ——– c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:40 30,674 ——– c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:40 30,674 ——– c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 ——– c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 ——– c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 ——– c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 ——– c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 3:54:14.48 ===============
"attach.txt" is attached in the file "attach_txt.zip"
Thanks again!