I got GMER to run. I disabled the computer's wireless connection and disabled the antivirus (AVG) and firewall (Comodo), which I should have done to begin with, and GMER ran fine. Here are the results:
——————————————————————–
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2011-02-12 19:40:16
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST916082 rev.3.CD
Running: kvjnsjeq.exe; Driver: C:\DOCUME~1\Mia\LOCALS~1\Temp\uxlyypod.sys
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 00395330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00395250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 00391800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003911D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 00391360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!EndTask 7E459E75 5 Bytes JMP 00394B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 00394E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!mouse_event 7E466515 5 Bytes JMP 00391670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003914F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 00394F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 00394880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003949F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A90D480 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A90D500 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A90D3E0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A90D3C0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A90D420 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A90D400 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A90D3A0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A90D550 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A90D560 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A90D581 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A90D650 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A90D620 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A90D590 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A90D2E0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A90D270 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A90D230 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A90D2B0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 00365330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00365250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!EndTask 7E459E75 5 Bytes JMP 00364B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 00364E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!mouse_event 7E466515 5 Bytes JMP 00361670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003614F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 00364F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 00361800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003611D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 00361360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 00364880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003649F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 003A5330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 003A5250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 003A1800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003A11D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 003A1360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!EndTask 7E459E75 5 Bytes JMP 003A4B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 003A4E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!mouse_event 7E466515 5 Bytes JMP 003A1670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003A14F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 003A4F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 003A4880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003A49F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 00365330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00365250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 00361800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003611D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 00361360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!EndTask 7E459E75 5 Bytes JMP 00364B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 00364E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!mouse_event 7E466515 5 Bytes JMP 00361670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003614F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 00364F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 00364880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003649F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
Device \FileSystem\Fastfat \Fat 9C863C8A
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@
—- EOF - GMER 1.0.15 —-