This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Computer - do I have malware?

288 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running Windows Vista Home Basic with service pack 2. Everything has been really slow since Christmas. I think my grandkids did something to it. Can you help me?

Here is the OTL log file.

OTL logfile created on: 3/18/2011 8:06:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:UsersReamDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 222.92 Gb Total Space | 145.23 Gb Free Space | 65.15% Space Free | Partition Type: NTFS
Drive D: | 9.96 Gb Total Space | 1.32 Gb Free Space | 13.30% Space Free | Partition Type: NTFS
Drive E: | 3.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REAM-PC | User Name: Ream | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:UsersReamDesktopOTL.exe
PRC - [2010/11/01 16:15:12 | 000,886,752 | —- | M] () – C:Program FilesSelectRebatesSelectRebates.exe
PRC - [2010/10/27 20:17:52 | 000,207,424 | —- | M] (ArcSoft Inc.) – C:Program FilesCommon FilesArcSoftConnection ServiceBinACDaemon.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:Program FilesCommon FilesArcSoftConnection ServiceBinACService.exe
PRC - [2010/02/05 17:19:46 | 000,065,256 | —- | M] (Microsoft Corporation) – C:Program FilesMicrosoft Windows OneCare Livewinssnotify.exe
PRC - [2010/02/05 17:19:44 | 001,141,112 | —- | M] (Microsoft Corporation) – C:Program FilesMicrosoft Windows OneCare Livewinss.exe
PRC - [2010/02/05 17:19:42 | 000,026,120 | —- | M] (Microsoft Corporation) – C:Program FilesMicrosoft Windows OneCare LiveOcHealthMon.exe
PRC - [2010/02/02 11:13:54 | 000,070,928 | —- | M] (PC Tools) – C:Program FilesSpyware DoctorTFEngineTFService.exe
PRC - [2010/01/21 19:21:02 | 000,112,592 | —- | M] (Threat Expert Ltd.) – C:Program FilesSpyware DoctorBDTBDTUpdateService.exe
PRC - [2010/01/18 15:14:36 | 001,593,808 | —- | M] (PC Tools) – C:Program FilesSpyware DoctorUpgrade.exe
PRC - [2010/01/18 15:14:26 | 001,286,608 | —- | M] (PC Tools) – C:Program FilesSpyware DoctorpctsTray.exe
PRC - [2010/01/18 15:14:24 | 001,141,712 | —- | M] (PC Tools) – C:Program FilesSpyware DoctorpctsSvc.exe
PRC - [2009/12/09 16:23:34 | 000,365,280 | —- | M] (PC Tools) – C:Program FilesSpyware DoctorpctsAuxs.exe
PRC - [2009/11/11 17:17:02 | 000,771,360 | —- | M] (Apple Inc.) – C:Program FilesAirPortAPAgent.exe
PRC - [2009/08/07 14:32:26 | 000,358,232 | —- | M] (Creative Home) – C:Program FilesCreative HomeHallmark Card Studio 2010 DeluxePlannerPLNRnote.exe
PRC - [2009/04/11 02:28:11 | 000,217,088 | —- | M] (Microsoft Corporation) – C:WindowsSystem32WerFault.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:Windowsexplorer.exe
PRC - [2009/04/08 06:38:14 | 000,251,240 | —- | M] (TomTom) – C:Program FilesTomTom HOME 2TomTomHOMERunner.exe
PRC - [2009/04/08 06:38:14 | 000,092,008 | —- | M] (TomTom) – C:Program FilesTomTom HOME 2TomTomHOMEService.exe
PRC - [2008/07/09 17:05:22 | 000,018,704 | —- | M] (Microsoft Corporation) – C:Program FilesMicrosoft Windows OneCare LiveAntivirusMsMpEng.exe
PRC - [2008/07/03 11:37:24 | 000,812,952 | —- | M] (PC Tools) – C:Program FilesRegistry MechanicRMTray.exe
PRC - [2008/01/20 22:32:50 | 000,215,552 | —- | M] (Microsoft Corporation) – C:WindowsWindowsMobilewmdSync.exe
PRC - [2007/11/27 22:45:02 | 000,869,952 | —- | M] (Microsoft Corporation) – C:Program FilesMicrosoft Windows OneCare LiveFirewallmsfwsvc.exe
PRC - [2007/04/18 11:01:34 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:hpsupporthpsysdrv.exe


========== Modules (SafeList) ==========

MOD - [2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:UsersReamDesktopOTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:Windowswinsxsx86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3comctl32.dll
MOD - [2010/02/02 11:13:54 | 000,451,856 | —- | M] (PC Tools) – C:Program FilesSpyware DoctorTFEngineTFWAH.dll
MOD - [2009/09/09 23:54:58 | 000,155,184 | —- | M] (PC Tools) – C:Program FilesSpyware Doctorsmum32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/04/02 22:34:12 | 000,073,728 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:Program FilesCommon FilesSony SharedFskSonySCSIHelperService.exe – (Sony SCSI Helper Service)
SRV - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:Program FilesCommon FilesArcSoftConnection ServiceBinACService.exe – (ACDaemon)
SRV - [2010/02/05 17:19:44 | 001,141,112 | —- | M] (Microsoft Corporation) [Auto | Running] – C:Program FilesMicrosoft Windows OneCare Livewinss.exe – (winss)
SRV - [2010/02/05 17:19:42 | 000,026,120 | —- | M] (Microsoft Corporation) [Auto | Running] – C:Program FilesMicrosoft Windows OneCare LiveOcHealthMon.exe – (OcHealthMon)
SRV - [2010/02/02 11:13:54 | 000,070,928 | —- | M] (PC Tools) [On_Demand | Running] – C:Program FilesSpyware DoctorTFEngineTFService.exe – (ThreatFire)
SRV - [2010/01/21 19:21:02 | 000,112,592 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:Program FilesSpyware DoctorBDTBDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/01/18 15:14:24 | 001,141,712 | —- | M] (PC Tools) [Auto | Running] – C:Program FilesSpyware DoctorpctsSvc.exe – (sdCoreService)
SRV - [2009/12/09 16:23:34 | 000,365,280 | —- | M] (PC Tools) [Auto | Running] – C:Program FilesSpyware DoctorpctsAuxs.exe – (sdAuxService)
SRV - [2009/04/08 06:38:14 | 000,092,008 | —- | M] (TomTom) [Auto | Running] – C:Program FilesTomTom HOME 2TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2008/07/09 17:05:22 | 000,018,704 | —- | M] (Microsoft Corporation) [Auto | Running] – C:Program FilesMicrosoft Windows OneCare LiveAntivirusMsMpEng.exe – (OneCareMP)
SRV - [2008/02/03 16:00:00 | 000,129,992 | —- | M] (EasyBits Sofware AS) [Auto | Running] – C:WindowsSystem32ezsvc7.dll – (ezSharedSvc)
SRV - [2008/01/20 22:33:00 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:Program FilesWindows DefenderMpSvc.dll – (WinDefend)
SRV - [2008/01/20 22:32:50 | 000,365,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:WindowsWindowsMobilewcescomm.dll – (WcesComm)
SRV - [2008/01/20 22:32:50 | 000,167,936 | —- | M] (Microsoft Corporation) [Auto | Running] – C:WindowsWindowsMobilerapimgr.dll – (RapiMgr)
SRV - [2007/11/27 22:45:02 | 000,869,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:Program FilesMicrosoft Windows OneCare LiveFirewallmsfwsvc.exe – (msfwsvc)


========== Driver Services (SafeList) ==========

DRV - [2010/02/05 10:25:38 | 000,070,408 | —- | M] (PC Tools) [Kernel | On_Demand | Running] – C:WindowsSystem32driverspctplsg.sys – (pctplsg)
DRV - [2010/02/05 10:17:56 | 000,233,136 | —- | M] (PC Tools) [Kernel | System | Running] – C:WindowsSystem32driverspctgntdi.sys – (pctgntdi)
DRV - [2010/02/02 11:13:54 | 000,059,664 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:Windowssystem32driversTfSysMon.sys – (TfSysMon)
DRV - [2010/02/02 11:13:54 | 000,051,984 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:Windowssystem32driversTfFsMon.sys – (TfFsMon)
DRV - [2010/02/02 11:13:54 | 000,033,552 | –S- | M] (PC Tools) [Kernel | On_Demand | Running] – C:WindowsSystem32driversTfNetMon.sys – (TfNetMon)
DRV - [2009/09/23 17:10:06 | 000,207,280 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:Windowssystem32driversPCTCore.sys – (PCTCore)
DRV - [2008/06/06 15:13:40 | 000,133,152 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:Windowssystem32driversnvrd32.sys – (nvrd32)
DRV - [2008/06/06 15:13:10 | 000,145,440 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:Windowssystem32DRIVERSnvstor32.sys – (nvstor32)
DRV - [2008/05/22 05:39:34 | 000,015,360 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:Windowssystem32driversnvsmu.sys – (nvsmu)
DRV - [2008/05/21 07:44:10 | 001,049,760 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:WindowsSystem32driversnvmfdx32.sys – (NVENETFD)
DRV - [2008/04/17 08:21:00 | 007,436,384 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:WindowsSystem32driversnvlddmkm.sys – (nvlddmkm)
DRV - [2008/02/12 11:27:34 | 000,207,360 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:WindowsSystem32driversHSXHWBS3.sys – (HSXHWBS3)
DRV - [2008/02/12 11:25:22 | 000,985,600 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:WindowsSystem32driversHSX_DP.sys – (HSF_DP)
DRV - [2007/11/27 22:45:00 | 000,091,200 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:WindowsSystem32driversmsfwdrv.sys – (MSFWDrv)
DRV - [2007/11/27 22:44:54 | 000,037,440 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:WindowsSystem32driversmsfwhlpr.sys – (MSFWHLPR)
DRV - [2007/10/18 11:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:WindowsSystem32driversXAudio.sys – (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,StartPageCache = 1
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.wane.com/"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23


FF - [removed]: C:Program FilesHPDigital ImagingSmart Web PrintingMozillaAddOn3 [2010/01/13 09:25:14 | 000,000,000 | —D | M]
FF - HKLMsoftwaremozillaMozilla Firefox 3.6.15extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2011/03/18 17:39:51 | 000,000,000 | —D | M]
FF - HKLMsoftwaremozillaMozilla Firefox 3.6.15extensionsPlugins: C:Program FilesMozilla Firefoxplugins [2011/03/18 17:39:51 | 000,000,000 | —D | M]

[2009/03/14 12:32:48 | 000,000,000 | —D | M] (No name found) – C:UsersReamAppDataRoamingMozillaExtensions
[2009/03/14 12:32:48 | 000,000,000 | —D | M] (No name found) – C:[removed]
[2011/03/18 16:54:23 | 000,000,000 | —D | M] (No name found) – C:UsersReamAppDataRoamingMozillaFirefoxProfiles6r5jgxy6.defaultextensio
ns
[2010/04/27 09:08:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:UsersReamAppDataRoamingMozillaFirefoxProfiles6r5jgxy6.defaultextensio
ns{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/07 17:33:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:UsersReamAppDataRoamingMozillaFirefoxProfiles6r5jgxy6.defaultextensio
ns{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/09/14 06:58:02 | 000,000,000 | —D | M] (Personas) – C:UsersReamAppDataRoamingMozillaFirefoxProfiles6r5jgxy6.defaultextensio
[removed]
[2010/12/25 18:56:22 | 000,000,000 | —D | M] (ShopAtHome.com Intelligent Shopping Toolbar) – C:UsersReamAppDataRoamingMozillaFirefoxProfiles6r5jgxy6.defaultextensio
[removed]
[2011/01/30 09:33:15 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2010/04/26 08:52:13 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/07 11:38:16 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/22 08:15:12 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/30 09:33:15 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:Program FilesMozilla FirefoxpluginsnpCouponPrinter.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:Program FilesMozilla FirefoxpluginsnpdeployJava1.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:Program FilesMozilla FirefoxpluginsnpMozCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:WindowsSystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:Program FilesSpyware DoctorBDTPCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:Program FilesSelectRebatesToolbarShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM..Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:Program FilesSpyware DoctorBDTPCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM..Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:Program FilesSelectRebatesToolbarShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM..Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O3 - HKCU..ToolbarWebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:Program FilesSpyware DoctorBDTPCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU..ToolbarWebBrowser: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:Program FilesSelectRebatesToolbarShopAtHomeToolbar.dll (ShopAtHome.com)
O4 - HKLM..Run: [AirPort Base Station Agent] C:Program FilesAirPortAPAgent.exe (Apple Inc.)
O4 - HKLM..Run: [ArcSoft Connection Service] C:Program FilesCommon FilesArcSoftConnection ServiceBinACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..Run: [DPService] C:Program FilesHPDVDPlayDPService.exe (CyberLink Corp.)
O4 - HKLM..Run: [hpqSRMon] File not found
O4 - HKLM..Run: [hpsysdrv] c:hpsupporthpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..Run: [ISTray] C:Program FilesSpyware DoctorpctsTray.exe (PC Tools)
O4 - HKLM..Run: [NvCplDaemon] C:WindowsSystem32NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..Run: [NvMediaCenter] C:WindowsSystem32NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..Run: [OneCareUI] C:Program FilesMicrosoft Windows OneCare Livewinssnotify.exe (Microsoft Corporation)
O4 - HKLM..Run: [SelectRebates] C:Program FilesSelectRebatesSelectRebates.exe ()
O4 - HKLM..Run: [Windows Defender] C:Program FilesWindows DefenderMSASCui.exe (Microsoft Corporation)
O4 - HKLM..Run: [Windows Mobile-based device management] C:WindowsWindowsMobilewmdSync.exe (Microsoft Corporation)
O4 - HKCU..Run: [RegistryMechanic] C:Program FilesRegistry MechanicRMTray.exe (PC Tools)
O4 - HKCU..Run: [TomTomHOME.exe] C:Program FilesTomTom HOME 2TomTomHOMERunner.exe (TomTom)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: HideFastUserSwitching = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoLogoff = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoClose = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DisableLockWorkstation = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DisableChangePassword = 0
O10 - NameSpace_Catalog5Catalog_Entries\000000000007 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9Catalog_Entries\000000000001 - C:Program FilesCommon FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000002 - C:Program FilesCommon FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000003 - C:Program FilesCommon FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000014 - C:Program FilesCommon FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Jojo's%20Fashion%20Show/Images/armhelper.ocx (ArmHelper Control)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 10.0.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:Windowssystem32ezShellStart.exe) - C:WindowsSystem32ezShellStart.exe (EasyBits Software AS)
O24 - Desktop WallPaper: C:UsersReamPictures2008-06 (Jun)HPIM0820.JPG
O24 - Desktop BackupWallPaper: C:UsersReamPictures2008-06 (Jun)HPIM0820.JPG
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:WindowsSystem32ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/04 14:24:08 | 000,000,074 | —- | M] () - C:autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/12/02 20:08:49 | 000,000,042 | R— | M] () - E:autorun.inf – [ CDFS ]
O33 - MountPoints2{7734968a-10a6-11de-bbae-002354a3bf64}ShellAutoRuncommand - "" = K:Launch.exe
O33 - MountPoints2{96f7cda1-f3a3-11dd-a933-806e6f6e6963}Shell - "" = AutoRun
O33 - MountPoints2{96f7cda1-f3a3-11dd-a933-806e6f6e6963}ShellAutoRuncommand - "" = E:setup.exe – [2008/12/02 20:08:49 | 000,132,680 | R— | M] (Macrovision Corporation)
O33 - MountPoints2{c5a741f6-1624-11de-8e70-002354a3bf64}ShellAutoRuncommand - "" = L:InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: ezSharedSvc - C:WindowsSystem32ezsvc7.dll (EasyBits Sofware AS)

Drivers32: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:WindowsSystem32iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/03/18 20:03:18 | 000,580,608 | —- | C] (OldTimer Tools) – C:UsersReamDesktopOTL.exe
[2011/03/09 10:08:35 | 000,429,056 | —- | C] (Microsoft Corporation) – C:WindowsSystem32EncDec.dll
[2011/03/09 10:08:34 | 000,322,560 | —- | C] (Microsoft Corporation) – C:WindowsSystem32sbe.dll
[2011/03/09 10:08:34 | 000,177,664 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mpg2splt.ax
[2011/03/09 10:08:34 | 000,153,088 | —- | C] (Microsoft Corporation) – C:WindowsSystem32sbeio.dll
[2011/02/25 08:36:50 | 000,000,000 | —D | C] – C:WindowsSystem32WindowsPowerShell
[2011/02/25 08:34:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winrsmgr.dll
[2011/02/25 08:33:42 | 000,040,448 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winrs.exe
[2011/02/25 08:33:42 | 000,020,480 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winrshost.exe
[2011/02/25 08:33:42 | 000,012,800 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wsmprovhost.exe
[2011/02/25 08:33:39 | 000,010,240 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wsmplpxy.dll
[2011/02/25 08:33:38 | 000,010,240 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winrssrv.dll
[2011/02/25 08:33:35 | 000,081,408 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wevtfwd.dll
[2011/02/25 08:33:35 | 000,079,872 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wecutil.exe
[2011/02/25 08:33:35 | 000,056,320 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wecapi.dll
[2011/02/25 08:33:35 | 000,054,272 | —- | C] (Microsoft Corporation) – C:WindowsSystem32WsmRes.dll
[2011/02/25 08:33:35 | 000,041,472 | —- | C] (Microsoft Corporation) – C:WindowsSystem32pwrshplugin.dll
[2011/02/25 08:33:16 | 000,214,016 | —- | C] (Microsoft Corporation) – C:WindowsSystem32WsmWmiPl.dll
[2011/02/25 08:33:16 | 000,145,408 | —- | C] (Microsoft Corporation) – C:WindowsSystem32WsmAuto.dll
[2011/02/25 08:33:15 | 000,252,416 | —- | C] (Microsoft Corporation) – C:WindowsSystem32WSManMigrationPlugin.dll
[2011/02/25 08:33:15 | 000,246,272 | —- | C] (Microsoft Corporation) – C:WindowsSystem32WSManHTTPConfig.exe
[2011/02/25 08:33:15 | 000,241,152 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winrscmd.dll

========== Files - Modified Within 30 Days ==========

[2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:UsersReamDesktopOTL.exe
[2011/03/18 18:43:37 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/18 18:43:37 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/18 17:37:22 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2011/03/18 16:44:19 | 000,165,888 | —- | M] () – C:UsersReamDocumentsNational city checking.mny
[2011/03/18 14:10:57 | 000,642,668 | —- | M] () – C:WindowsSystem32perfh009.dat
[2011/03/18 14:10:57 | 000,119,858 | —- | M] () – C:WindowsSystem32perfc009.dat

here is the OTL extras log.

OTL Extras logfile created on: 3/18/2011 8:06:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:UsersReamDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 222.92 Gb Total Space | 145.23 Gb Free Space | 65.15% Space Free | Partition Type: NTFS
Drive D: | 9.96 Gb Total Space | 1.32 Gb Free Space | 13.30% Space Free | Partition Type: NTFS
Drive E: | 3.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REAM-PC | User Name: Ream | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSystem32control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:Windowswinhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = FirefoxHTML] – C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%system32mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
Hello sue ream and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Both of your OTL logs appear to be incomplete. Please post the complete logs in your next reply along with the log created from the following tool. If you need to make multiple posts to fit all of the information in by all means do so :)

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click on GMER.exe and select "Run as Administrator" to run the program. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have any trouble with the scan just let me know.
My mom is having trouble posting, so she emailed me the logs and I will post them for her (I posted the first ones).

Here is the OTL Log again. Hopefully this is complete.

OTL logfile created on: 3/18/2011 8:06:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Ream\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.92 Gb Total Space | 145.23 Gb Free Space | 65.15% Space Free | Partition Type: NTFS
Drive D: | 9.96 Gb Total Space | 1.32 Gb Free Space | 13.30% Space Free | Partition Type: NTFS
Drive E: | 3.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REAM-PC | User Name: Ream | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Ream\Desktop\OTL.exe
PRC - [2010/11/01 16:15:12 | 000,886,752 | —- | M] () – C:\Program Files\SelectRebates\SelectRebates.exe
PRC - [2010/10/27 20:17:52 | 000,207,424 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/02/05 17:19:46 | 000,065,256 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
PRC - [2010/02/05 17:19:44 | 001,141,112 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Windows OneCare Live\winss.exe
PRC - [2010/02/05 17:19:42 | 000,026,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
PRC - [2010/02/02 11:13:54 | 000,070,928 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
PRC - [2010/01/21 19:21:02 | 000,112,592 | —- | M] (Threat Expert Ltd.) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2010/01/18 15:14:36 | 001,593,808 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\Upgrade.exe
PRC - [2010/01/18 15:14:26 | 001,286,608 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2010/01/18 15:14:24 | 001,141,712 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2009/12/09 16:23:34 | 000,365,280 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2009/11/11 17:17:02 | 000,771,360 | —- | M] (Apple Inc.) – C:\Program Files\AirPort\APAgent.exe
PRC - [2009/08/07 14:32:26 | 000,358,232 | —- | M] (Creative Home) – C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe
PRC - [2009/04/11 02:28:11 | 000,217,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/04/08 06:38:14 | 000,251,240 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2009/04/08 06:38:14 | 000,092,008 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2008/07/09 17:05:22 | 000,018,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
PRC - [2008/07/03 11:37:24 | 000,812,952 | —- | M] (PC Tools) – C:\Program Files\Registry Mechanic\RMTray.exe
PRC - [2008/01/20 22:32:50 | 000,215,552 | —- | M] (Microsoft Corporation) – C:\Windows\WindowsMobile\wmdSync.exe
PRC - [2007/11/27 22:45:02 | 000,869,952 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
PRC - [2007/04/18 11:01:34 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe


========== Modules (SafeList) ==========

MOD - [2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Ream\Desktop\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2010/02/02 11:13:54 | 000,451,856 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\TFEngine\TFWAH.dll
MOD - [2009/09/09 23:54:58 | 000,155,184 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\smum32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/04/02 22:34:12 | 000,073,728 | —- | M] (Sony Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe – (Sony SCSI Helper Service)
SRV - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2010/02/05 17:19:44 | 001,141,112 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Windows OneCare Live\winss.exe – (winss)
SRV - [2010/02/05 17:19:42 | 000,026,120 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe – (OcHealthMon)
SRV - [2010/02/02 11:13:54 | 000,070,928 | —- | M] (PC Tools) [On_Demand | Running] – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe – (ThreatFire)
SRV - [2010/01/21 19:21:02 | 000,112,592 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/01/18 15:14:24 | 001,141,712 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService)
SRV - [2009/12/09 16:23:34 | 000,365,280 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService)
SRV - [2009/04/08 06:38:14 | 000,092,008 | —- | M] (TomTom) [Auto | Running] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2008/07/09 17:05:22 | 000,018,704 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe – (OneCareMP)
SRV - [2008/02/03 16:00:00 | 000,129,992 | —- | M] (EasyBits Sofware AS) [Auto | Running] – C:\Windows\System32\ezsvc7.dll – (ezSharedSvc)
SRV - [2008/01/20 22:33:00 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/20 22:32:50 | 000,365,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\WindowsMobile\wcescomm.dll – (WcesComm)
SRV - [2008/01/20 22:32:50 | 000,167,936 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\WindowsMobile\rapimgr.dll – (RapiMgr)
SRV - [2007/11/27 22:45:02 | 000,869,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe – (msfwsvc)


========== Driver Services (SafeList) ==========

DRV - [2010/02/05 10:25:38 | 000,070,408 | —- | M] (PC Tools) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\pctplsg.sys – (pctplsg)
DRV - [2010/02/05 10:17:56 | 000,233,136 | —- | M] (PC Tools) [Kernel | System | Running] – C:\Windows\System32\drivers\pctgntdi.sys – (pctgntdi)
DRV - [2010/02/02 11:13:54 | 000,059,664 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - [2010/02/02 11:13:54 | 000,051,984 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\TfFsMon.sys – (TfFsMon)
DRV - [2010/02/02 11:13:54 | 000,033,552 | –S- | M] (PC Tools) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\TfNetMon.sys – (TfNetMon)
DRV - [2009/09/23 17:10:06 | 000,207,280 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2008/06/06 15:13:40 | 000,133,152 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvrd32.sys – (nvrd32)
DRV - [2008/06/06 15:13:10 | 000,145,440 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2008/05/22 05:39:34 | 000,015,360 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvsmu.sys – (nvsmu)
DRV - [2008/05/21 07:44:10 | 001,049,760 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2008/04/17 08:21:00 | 007,436,384 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/02/12 11:27:34 | 000,207,360 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWBS3.sys – (HSXHWBS3)
DRV - [2008/02/12 11:25:22 | 000,985,600 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DP.sys – (HSF_DP)
DRV - [2007/11/27 22:45:00 | 000,091,200 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\msfwdrv.sys – (MSFWDrv)
DRV - [2007/11/27 22:44:54 | 000,037,440 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\msfwhlpr.sys – (MSFWHLPR)
DRV - [2007/10/18 11:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: " target=_blank >http://www.wane.com/"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:5.2.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/13 09:25:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/18 17:39:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/18 17:39:51 | 000,000,000 | —D | M]

[2009/03/14 12:32:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Ream\AppData\Roaming\Mozilla\Extensions
[2009/03/14 12:32:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Ream\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/03/18 16:54:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Ream\AppData\Roaming\Mozilla\Firefox\Profiles\6r5jgxy6.default\extensions
[2010/04/27 09:08:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Ream\AppData\Roaming\Mozilla\Firefox\Profiles\6r5jgxy6.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/07 17:33:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Ream\AppData\Roaming\Mozilla\Firefox\Profiles\6r5jgxy6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/09/14 06:58:02 | 000,000,000 | —D | M] (Personas) – C:\Users\Ream\AppData\Roaming\Mozilla\Firefox\Profiles\6r5jgxy6.default\extensions\[removed]
[2010/12/25 18:56:22 | 000,000,000 | —D | M] (ShopAtHome.com Intelligent Shopping Toolbar) – C:\Users\Ream\AppData\Roaming\Mozilla\Firefox\Profiles\6r5jgxy6.default\extensions\[removed]
[2011/01/30 09:33:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 08:52:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/07 11:38:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/22 08:15:12 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/30 09:33:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O4 - HKLM..\Run: [AirPort Base Station Agent] C:\Program Files\AirPort\APAgent.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DPService] C:\Program Files\HP\DVDPlay\DPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [hpqSRMon]  File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OneCareUI] C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe (PC Tools)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} target=_blank >http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Jojo's%20Fashion%20Show/Images/armhelper.ocx (ArmHelper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\ezShellStart.exe) - C:\Windows\System32\ezShellStart.exe (EasyBits Software AS)
O24 - Desktop WallPaper: C:\Users\Ream\Pictures\2008-06 (Jun)\HPIM0820.JPG
O24 - Desktop BackupWallPaper: C:\Users\Ream\Pictures\2008-06 (Jun)\HPIM0820.JPG
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\System32\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/04 14:24:08 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/12/02 20:08:49 | 000,000,042 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7734968a-10a6-11de-bbae-002354a3bf64}\Shell\AutoRun\command - "" = K:\Launch.exe
O33 - MountPoints2\{96f7cda1-f3a3-11dd-a933-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{96f7cda1-f3a3-11dd-a933-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe – [2008/12/02 20:08:49 | 000,132,680 | R— | M] (Macrovision Corporation)
O33 - MountPoints2\{c5a741f6-1624-11de-8e70-002354a3bf64}\Shell\AutoRun\command - "" = L:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
NetSvcs: ezSharedSvc - C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/03/18 20:03:18 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Ream\Desktop\OTL.exe
[2011/03/09 10:08:35 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 10:08:34 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 10:08:34 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/09 10:08:34 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/02/25 08:36:50 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2011/02/25 08:34:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2011/02/25 08:33:42 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2011/02/25 08:33:42 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2011/02/25 08:33:42 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2011/02/25 08:33:39 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2011/02/25 08:33:38 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2011/02/25 08:33:35 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2011/02/25 08:33:35 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2011/02/25 08:33:35 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2011/02/25 08:33:35 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2011/02/25 08:33:35 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2011/02/25 08:33:16 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2011/02/25 08:33:16 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2011/02/25 08:33:15 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2011/02/25 08:33:15 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2011/02/25 08:33:15 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll

========== Files - Modified Within 30 Days ==========

[2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Ream\Desktop\OTL.exe
[2011/03/18 18:43:37 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/18 18:43:37 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/18 17:37:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/18 16:44:19 | 000,165,888 | —- | M] () – C:\Users\Ream\Documents\National city checking.mny
[2011/03/18 14:10:57 | 000,642,668 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/03/18 14:10:57 | 000,119,858 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/03/18 14:04:32 | 2145,890,304 | -HS- | M] () – C:\hiberfil.sys
[2011/03/15 20:00:52 | 000,000,832 | —- | M] () – C:\Users\Ream\AppData\Roaming\wklnhst.dat
[2011/03/14 10:39:31 | 000,024,576 | —- | M] () – C:\Users\Ream\Documents\bills for 2011.xlr
[2011/03/06 13:56:35 | 000,000,318 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForReam.job

========== Files Created - No Company Name ==========

[2011/02/25 08:33:21 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2011/02/25 08:33:21 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2011/02/25 08:33:20 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2010/06/30 00:12:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2010/03/19 09:58:02 | 000,001,356 | —- | C] () – C:\Users\Ream\AppData\Local\d3d9caps.dat
[2010/02/26 22:18:22 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2010/02/26 22:18:22 | 000,767,928 | —- | C] () – C:\Windows\BDTSupport.dll
[2010/01/13 09:24:44 | 000,023,111 | —- | C] () – C:\Windows\hpqins15.dat
[2009/11/17 21:33:31 | 000,077,350 | —- | C] () – C:\Windows\hpqins05.dat
[2009/08/18 15:14:30 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/18 15:14:29 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/11 21:18:24 | 000,007,168 | —- | C] () – C:\Users\Ream\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/07 16:56:21 | 000,167,849 | —- | C] () – C:\Windows\hpqins00.dat
[2009/04/25 08:55:28 | 000,000,575 | —- | C] () – C:\Windows\hegames.ini
[2009/03/13 21:44:09 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2009/03/13 15:06:01 | 000,157,529 | —- | C] () – C:\Windows\hpoins28.dat
[2009/03/13 09:18:02 | 000,000,000 | —- | C] () – C:\Windows\MSREGUSR.INI
[2009/03/13 09:10:35 | 000,306,688 | —- | C] () – C:\Windows\System32\LFFPX7.DLL
[2009/03/13 09:10:35 | 000,095,232 | —- | C] () – C:\Windows\System32\LFKODAK.DLL
[2009/03/13 09:10:26 | 000,044,544 | —- | C] () – C:\Windows\System32\gif89.dll
[2009/03/13 09:09:55 | 000,000,518 | —- | C] () – C:\Windows\SIERRA.INI
[2009/03/12 21:21:19 | 000,000,832 | —- | C] () – C:\Users\Ream\AppData\Roaming\wklnhst.dat
[2009/02/04 14:36:48 | 000,008,292 | —- | C] () – C:\Windows\System32\ezdigsgn.dat
[2009/02/04 14:25:07 | 000,107,357 | —- | C] () – C:\Windows\hpqins13.dat
[2009/02/04 14:10:57 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2009/02/04 14:10:57 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2009/02/04 13:59:36 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2007/12/12 20:01:47 | 000,000,932 | —- | C] () – C:\Windows\hpomdl28.dat
[2006/11/02 08:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:44:53 | 000,532,072 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:33:01 | 000,642,668 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,119,858 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[1996/09/02 00:00:00 | 000,041,472 | —- | C] () – C:\Windows\System32\WOSAXRT.DLL
[1996/09/02 00:00:00 | 000,006,656 | —- | C] () – C:\Windows\System32\MSNWEBQT.DLL

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/02/04 14:24:08 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/02/04 13:50:12 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/02/18 11:18:59 | 000,000,045 | —- | M] () – C:\error.log
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/09/05 22:01:38 | 000,000,250 | —- | M] () – C:\FINIS_IT.TXT
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/03/18 14:04:32 | 2145,890,304 | -HS- | M] () – C:\hiberfil.sys
[2011/02/09 13:24:00 | 030,348,800 | —- | M] () – C:\HR Block 2010.msi
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/02/05 13:26:08 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/02/05 13:26:08 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/03/18 14:04:31 | 2459,705,344 | -HS- | M] () – C:\pagefile.sys
[2009/12/01 23:02:26 | 000,000,142 | —- | M] () – C:\pctlsp.log
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 08:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/04/29 09:52:07 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/01/20 22:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/10 20:06:27 | 000,000,574 | -HS- | M] () – C:\Users\Ream\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/03/18 20:04:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Ream\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-14 14:11:53

========== Alternate Data Streams ==========

@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 143 bytes -> C:\Users\Ream\Documents\tomato sauce.nws:OECustomProperty
@Alternate Data Stream - 143 bytes -> C:\Users\Ream\Documents\thanksgiving.nws:OECustomProperty
@Alternate Data Stream - 142 bytes -> C:\Windows\System32\lî:pctlsp.log
@Alternate Data Stream - 142 bytes -> C:\Windows\System32:NÁw²ÃwNÁwƾuìñwpctlsp.log
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:E70CF2C0
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:D94162E1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >

Inline Attachment Follows: Extras.Txt
OTL Extras logfile created on: 3/18/2011 8:06:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Ream\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.92 Gb Total Space | 145.23 Gb Free Space | 65.15% Space Free | Partition Type: NTFS
Drive D: | 9.96 Gb Total Space | 1.32 Gb Free Space | 13.30% Space Free | Partition Type: NTFS
Drive E: | 3.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REAM-PC | User Name: Ream | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1E77EE04-13B1-42CD-9D95-AA92BE0B742B}" = lport=445 | protocol=6 | dir=in | app=system |
"{23EA1451-C347-4C83-93DD-4FB66F304A74}" = rport=139 | protocol=6 | dir=out | app=system |
"{49151A81-F427-4E53-8335-4CD1F5D57BAC}" = rport=137 | protocol=17 | dir=out | app=system |
"{49760E3E-01FC-4FA5-A433-38FCFE4CFED5}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{4DCCA8E3-7DE8-4A94-8593-44CF8D6E11B5}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5ED9A6BC-D465-4B42-9F6D-082AC685377B}" = lport=138 | protocol=17 | dir=in | app=system |
"{6BDD1F18-29ED-4178-AC7A-5A4631C67780}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9BCB8E6D-48ED-427E-BB5B-8F74D668025A}" = rport=138 | protocol=17 | dir=out | app=system |
"{9EC75290-59BF-4651-9590-D9EF8933E452}" = lport=139 | protocol=6 | dir=in | app=system |
"{A9ECE8F6-0632-4D4F-8638-B9306B09C4A3}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{AAF2A924-69A3-4DF7-83C0-A60CCE61696E}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{C21FEB1B-FF48-404C-B064-4799181A198A}" = lport=137 | protocol=17 | dir=in | app=system |
"{DEBC70CD-CFB7-43D3-B9F3-9B2F765CB53B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E29A906B-2E9C-4272-B678-1D1FAF1E7F2F}" = rport=445 | protocol=6 | dir=out | app=system |
"{E78F97A5-F29B-4492-AE19-4312793BD428}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CFE44FE-0C27-4341-91D5-3679408060FD}" = dir=in | app=c:\program files\hp\dvdplay\dvdplay.exe |
"{10233E5F-5CBC-4697-8860-3CF38432E916}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{279405D8-D5B6-4F46-B0D4-BF32BA4715BA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{3807FF12-6329-4935-AFC5-C9B4A04D17E9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3FE04C7A-585B-4274-9C54-11624F4C5B8A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4211C5BD-9B0A-42AE-B1E4-9FCF5674D03C}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{46E4E5F3-8EB6-4A5B-B17D-7F5578D8C449}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{49D0275A-7E94-4D65-B550-2F6FFD8CF050}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{4C14DBE7-A205-4A55-A68F-50B6406877B5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4D2D7971-F181-4528-87D1-A1B088D7AE2F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{544254E9-E809-4ECF-BFA1-6C8A17F57D9B}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{58975AEB-2C6F-498A-AE3E-61F2A248FECC}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{5A003F39-8EA5-438C-93E6-9632156E6C31}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{728D88FE-6545-47FC-9BC8-C7EE44E9BA7C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{73B131D6-BE8E-41FC-93FA-0F193B8A3C5A}" = dir=in | app=c:\program files\hp\dvdplay\dpservice.exe |
"{982CFF85-F3B6-4A13-B7DE-1DBA12E4D0A6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{998B5B08-6EEE-422D-86D5-A68B078947D0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BFBEBE9E-622E-4573-917E-1A4680A6E6D3}" = protocol=6 | dir=in | app=c:\program files\airport\apagent.exe |
"{C62EFE02-EDD5-4D61-8C57-CECCDA0B30EF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{C6C33BAF-6DF9-4AD5-AAFB-63C5825D3195}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{D1D7710E-F7FB-428F-899C-2B2AD555D3BF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{D20354C3-8012-4B82-861D-AC10BEC73813}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{E0C7F968-4E6F-4891-8130-B3B54BD869E0}" = protocol=17 | dir=in | app=c:\program files\airport\apagent.exe |
"{F3AC44DA-989A-435C-B38B-4715BDDBB396}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F879FB62-508C-4533-B08F-1A055E5E8CD9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{10964A8F-21C1-45EA-BC2D-F84B505C3848}" = H&R Block Deluxe + Efile + State 2010
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 23
"{2DDCB109-F81F-4307-9A2E-351BF0EC721D}" = 2010 Hallmark Registration Bonus Pack
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3851147E-5A91-4469-BA4D-13FFFCC8A920}" = Microsoft Windows OneCare Live v2.5.2900.20 Idcrl Install
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = DVD Play
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4C0F8A40-2273-43E1-8C61-40D7F0573EDE}" = AirPort
"{4D9C7DA3-D532-432D-A556-5F6CD186B0A5}" = DJ_AIO_03_F4200_ProductContext
"{53A19323-917A-4822-B27E-A57D1EF6E9FC}" = H&R Block Deluxe + Efile + State 2009
"{5660022E-F3F2-4126-8CC5-9726C47150EB}" = Microsoft Windows Live OneCare Resources v2.5.2900.30
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{601BE80D-247B-4084-94C7-7A54369DB7A2}" = Hallmark Card Studio 2010 Deluxe
"{62653245-3DC5-4019-AF6B-4E62D6150D9E}" = F4200_Help
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6513E869-647F-40FD-A55D-CFC92579B9BA}" = PX Engine
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67DFCE0D-BBA9-43AC-90B3-548390ECE522}" = F4200
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{71310D9B-7555-44FE-914C-A1B55CB7BC5D}" = Scrapbook
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{741849D8-E8D9-49CF-B373-0D7507ED0A56}" = Event Planner
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{84AD51C6-63EB-4E8F-8F66-7B17E5115AB0}" = H&R Block Indiana 2010
"{85E759A7-9FEF-4A51-9E19-E4D92432B579}" = PrintMaster 16
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B21B9EF-6DBF-4F63-8CC7-9F6A56D1EE8E}" = GTOneCare
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91029CA6-FAA2-40BB-829B-974D2DDD5298}" = Hallmark Christian Card Studio
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97F4D62E-5AEB-4649-BABF-4712C6EF6845}" = DeductionPro 2009
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{9DBCE8C7-FE94-4D8F-9FF0-38EF3D8BC99E}" = DJ_AIO_03_F4200_Software
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan
"{A212E6C2-20F7-4A8E-BD8E-DC3EE7483FA2}" = PRS-500 USB driver
"{A2FA012E-27C7-4308-9457-5FCFB84B0436}" = PictureMover
"{A35C2323-3CEA-405C-9569-EF5DDE930B2F}" = PrintMaster
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AE9A67F9-ADF1-4a44-BAB5-C1DB302B37A2}" = HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29B526D-F027-4122-BC7A-D9E5BC86CC40}" = DJ_AIO_03_F4200_Software_Min
"{B6977866-8AD6-46A1-9A85-F232BB6A25F6}" = CoPilot Health Management System
"{B70E5793-F912-4C62-AFE2-C4F0B078FD31}" = Reader Library by Sony
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B9AB88D8-3A09-4A4A-8993-0E2F6F9F294B}" = muvee autoProducer 6.1
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07A8E7E-D324-4945-BA8C-E532AD008FF3}" = Microsoft Windows OneCare Live v2.5.2900.30
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D94A8E22-DF2B-4107-9E51-608A60A7671D}" = Personal Ancestral File 5
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{E08BA611-5BB8-4AFC-BEE8-468D1AE5FFED}" = H&R Block Indiana 2009
"{E26B83D1-C0BB-41BC-8F44-31D5354DD6AF}" = Microsoft Windows OneCare Live AntiSpyware and AntiVirus
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B58D4E-7324-44E4-A6B3-65D2DB8D1FE9}" = Microsoft Protection Service
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FD011F34-749C-47E0-BA48-6009412C4789}" = ArcSoft Print Creations
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"75070B1806113224B16C70296B90DD1AD8A53479" = Windows Driver Package - Sony Corporation (PRSUSB) USB  (08/08/2006 1.0.03.08080)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"American Greetings Crafts! 1.00" = American Greetings Crafts! 1.00
"American Greetings Spiritual Expressions 1.00" = American Greetings Spiritual Expressions 1.00
"American Greetings® Art & More Store" = American Greetings® Art & More Store
"Browser Defender_is1" = Browser Defender 2.0.6.15
"CNXT_MODEM_PCI_HSF" = PCIe Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Digital Editions" = Adobe Digital Editions
"EasyBits Magic Desktop" = Magic Desktop
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"Jojo's Fashion Show" = Jojo's Fashion Show
"Magic 3D Coloring Book Cool Critters" = Magic 3D Coloring Book Cool Critters
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"MSMONEYV50" = Microsoft Money 5.0
"NVIDIA Drivers" = NVIDIA Drivers
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"PrintMaster Gold 4.00" = PrintMaster Gold 4.00
"QuickVerse Life Application Bible" = QuickVerse Life Application Bible
"Registry Mechanic_is1" = Registry Mechanic 8.0
"SelectRebatesUninstall" = ShopAtHome.com Toolbar
"Shockwave" = Shockwave
"Shop for HP Supplies" = Shop for HP Supplies
"sp43115" = sp43115
"sp44626" = sp44626
"Spyware Doctor" = Spyware Doctor 7.0
"TomTom HOME" = TomTom HOME 2.6.2.1586
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WildTangent hp Master Uninstall" = My HP Games
"WinSS" = Windows Live OneCare
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Smilebox" = Smilebox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/17/2011 2:02:01 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6053

Error - 2/17/2011 2:02:01 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6053

Error - 2/17/2011 2:02:02 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/17/2011 2:02:02 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7051

Error - 2/17/2011 2:02:02 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7051

Error - 2/17/2011 2:22:26 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/17/2011 2:22:26 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1014

Error - 2/17/2011 2:22:26 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1014

Error - 2/17/2011 2:22:27 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/17/2011 2:22:27 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2028

[ System Events ]
Error - 3/18/2011 7:45:34 AM | Computer Name = Ream-PC | Source = HTTP | ID = 15021
Description =

Error - 3/18/2011 7:46:59 AM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/18/2011 7:47:23 AM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 3/18/2011 11:13:02 AM | Computer Name = Ream-PC | Source = BROWSER | ID = 8007
Description =

Error - 3/18/2011 11:54:26 AM | Computer Name = Ream-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 10.0.1.2 on the
Network Card with network address 002354A3BF64.

Error - 3/18/2011 2:04:38 PM | Computer Name = Ream-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:51:35 PM on 3/18/2011 was unexpected.

Error - 3/18/2011 2:04:42 PM | Computer Name = Ream-PC | Source = HTTP | ID = 15021
Description =

Error - 3/18/2011 2:06:13 PM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/18/2011 2:06:47 PM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 3/18/2011 6:04:39 PM | Computer Name = Ream-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 10.0.1.2 on the
Network Card with network address 002354A3BF64.

[ Windows OneCare Events ]
Error - 2/14/2011 12:06:56 PM | Computer Name = Ream-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x8a190107.

Error - 2/14/2011 7:26:00 PM | Computer Name = Ream-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x8a190107.

Error - 2/16/2011 9:41:54 AM | Computer Name = Ream-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x8a190107.

Error - 2/18/2011 9:45:22 PM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 2/18/2011 9:47:03 PM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/15/2011 4:25:40 PM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:12:17 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:12:58 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:13:39 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:14:20 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb


< End of report >
Here is the OTL "Extras" log.


OTL Extras logfile created on: 3/18/2011 8:06:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Ream\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.92 Gb Total Space | 145.23 Gb Free Space | 65.15% Space Free | Partition Type: NTFS
Drive D: | 9.96 Gb Total Space | 1.32 Gb Free Space | 13.30% Space Free | Partition Type: NTFS
Drive E: | 3.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REAM-PC | User Name: Ream | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1E77EE04-13B1-42CD-9D95-AA92BE0B742B}" = lport=445 | protocol=6 | dir=in | app=system |
"{23EA1451-C347-4C83-93DD-4FB66F304A74}" = rport=139 | protocol=6 | dir=out | app=system |
"{49151A81-F427-4E53-8335-4CD1F5D57BAC}" = rport=137 | protocol=17 | dir=out | app=system |
"{49760E3E-01FC-4FA5-A433-38FCFE4CFED5}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{4DCCA8E3-7DE8-4A94-8593-44CF8D6E11B5}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5ED9A6BC-D465-4B42-9F6D-082AC685377B}" = lport=138 | protocol=17 | dir=in | app=system |
"{6BDD1F18-29ED-4178-AC7A-5A4631C67780}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9BCB8E6D-48ED-427E-BB5B-8F74D668025A}" = rport=138 | protocol=17 | dir=out | app=system |
"{9EC75290-59BF-4651-9590-D9EF8933E452}" = lport=139 | protocol=6 | dir=in | app=system |
"{A9ECE8F6-0632-4D4F-8638-B9306B09C4A3}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{AAF2A924-69A3-4DF7-83C0-A60CCE61696E}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{C21FEB1B-FF48-404C-B064-4799181A198A}" = lport=137 | protocol=17 | dir=in | app=system |
"{DEBC70CD-CFB7-43D3-B9F3-9B2F765CB53B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E29A906B-2E9C-4272-B678-1D1FAF1E7F2F}" = rport=445 | protocol=6 | dir=out | app=system |
"{E78F97A5-F29B-4492-AE19-4312793BD428}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CFE44FE-0C27-4341-91D5-3679408060FD}" = dir=in | app=c:\program files\hp\dvdplay\dvdplay.exe |
"{10233E5F-5CBC-4697-8860-3CF38432E916}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{279405D8-D5B6-4F46-B0D4-BF32BA4715BA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{3807FF12-6329-4935-AFC5-C9B4A04D17E9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3FE04C7A-585B-4274-9C54-11624F4C5B8A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4211C5BD-9B0A-42AE-B1E4-9FCF5674D03C}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{46E4E5F3-8EB6-4A5B-B17D-7F5578D8C449}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{49D0275A-7E94-4D65-B550-2F6FFD8CF050}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{4C14DBE7-A205-4A55-A68F-50B6406877B5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4D2D7971-F181-4528-87D1-A1B088D7AE2F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{544254E9-E809-4ECF-BFA1-6C8A17F57D9B}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{58975AEB-2C6F-498A-AE3E-61F2A248FECC}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{5A003F39-8EA5-438C-93E6-9632156E6C31}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{728D88FE-6545-47FC-9BC8-C7EE44E9BA7C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{73B131D6-BE8E-41FC-93FA-0F193B8A3C5A}" = dir=in | app=c:\program files\hp\dvdplay\dpservice.exe |
"{982CFF85-F3B6-4A13-B7DE-1DBA12E4D0A6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{998B5B08-6EEE-422D-86D5-A68B078947D0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BFBEBE9E-622E-4573-917E-1A4680A6E6D3}" = protocol=6 | dir=in | app=c:\program files\airport\apagent.exe |
"{C62EFE02-EDD5-4D61-8C57-CECCDA0B30EF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{C6C33BAF-6DF9-4AD5-AAFB-63C5825D3195}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{D1D7710E-F7FB-428F-899C-2B2AD555D3BF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{D20354C3-8012-4B82-861D-AC10BEC73813}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{E0C7F968-4E6F-4891-8130-B3B54BD869E0}" = protocol=17 | dir=in | app=c:\program files\airport\apagent.exe |
"{F3AC44DA-989A-435C-B38B-4715BDDBB396}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F879FB62-508C-4533-B08F-1A055E5E8CD9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{10964A8F-21C1-45EA-BC2D-F84B505C3848}" = H&R Block Deluxe + Efile + State 2010
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 23
"{2DDCB109-F81F-4307-9A2E-351BF0EC721D}" = 2010 Hallmark Registration Bonus Pack
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3851147E-5A91-4469-BA4D-13FFFCC8A920}" = Microsoft Windows OneCare Live v2.5.2900.20 Idcrl Install
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = DVD Play
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4C0F8A40-2273-43E1-8C61-40D7F0573EDE}" = AirPort
"{4D9C7DA3-D532-432D-A556-5F6CD186B0A5}" = DJ_AIO_03_F4200_ProductContext
"{53A19323-917A-4822-B27E-A57D1EF6E9FC}" = H&R Block Deluxe + Efile + State 2009
"{5660022E-F3F2-4126-8CC5-9726C47150EB}" = Microsoft Windows Live OneCare Resources v2.5.2900.30
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{601BE80D-247B-4084-94C7-7A54369DB7A2}" = Hallmark Card Studio 2010 Deluxe
"{62653245-3DC5-4019-AF6B-4E62D6150D9E}" = F4200_Help
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6513E869-647F-40FD-A55D-CFC92579B9BA}" = PX Engine
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67DFCE0D-BBA9-43AC-90B3-548390ECE522}" = F4200
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{71310D9B-7555-44FE-914C-A1B55CB7BC5D}" = Scrapbook
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{741849D8-E8D9-49CF-B373-0D7507ED0A56}" = Event Planner
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{84AD51C6-63EB-4E8F-8F66-7B17E5115AB0}" = H&R Block Indiana 2010
"{85E759A7-9FEF-4A51-9E19-E4D92432B579}" = PrintMaster 16
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B21B9EF-6DBF-4F63-8CC7-9F6A56D1EE8E}" = GTOneCare
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91029CA6-FAA2-40BB-829B-974D2DDD5298}" = Hallmark Christian Card Studio
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97F4D62E-5AEB-4649-BABF-4712C6EF6845}" = DeductionPro 2009
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{9DBCE8C7-FE94-4D8F-9FF0-38EF3D8BC99E}" = DJ_AIO_03_F4200_Software
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan
"{A212E6C2-20F7-4A8E-BD8E-DC3EE7483FA2}" = PRS-500 USB driver
"{A2FA012E-27C7-4308-9457-5FCFB84B0436}" = PictureMover
"{A35C2323-3CEA-405C-9569-EF5DDE930B2F}" = PrintMaster
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AE9A67F9-ADF1-4a44-BAB5-C1DB302B37A2}" = HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29B526D-F027-4122-BC7A-D9E5BC86CC40}" = DJ_AIO_03_F4200_Software_Min
"{B6977866-8AD6-46A1-9A85-F232BB6A25F6}" = CoPilot Health Management System
"{B70E5793-F912-4C62-AFE2-C4F0B078FD31}" = Reader Library by Sony
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B9AB88D8-3A09-4A4A-8993-0E2F6F9F294B}" = muvee autoProducer 6.1
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07A8E7E-D324-4945-BA8C-E532AD008FF3}" = Microsoft Windows OneCare Live v2.5.2900.30
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D94A8E22-DF2B-4107-9E51-608A60A7671D}" = Personal Ancestral File 5
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{E08BA611-5BB8-4AFC-BEE8-468D1AE5FFED}" = H&R Block Indiana 2009
"{E26B83D1-C0BB-41BC-8F44-31D5354DD6AF}" = Microsoft Windows OneCare Live AntiSpyware and AntiVirus
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B58D4E-7324-44E4-A6B3-65D2DB8D1FE9}" = Microsoft Protection Service
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FD011F34-749C-47E0-BA48-6009412C4789}" = ArcSoft Print Creations
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"75070B1806113224B16C70296B90DD1AD8A53479" = Windows Driver Package - Sony Corporation (PRSUSB) USB (08/08/2006 1.0.03.08080)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"American Greetings Crafts! 1.00" = American Greetings Crafts! 1.00
"American Greetings Spiritual Expressions 1.00" = American Greetings Spiritual Expressions 1.00
"American Greetings® Art & More Store" = American Greetings® Art & More Store
"Browser Defender_is1" = Browser Defender 2.0.6.15
"CNXT_MODEM_PCI_HSF" = PCIe Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Digital Editions" = Adobe Digital Editions
"EasyBits Magic Desktop" = Magic Desktop
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"Jojo's Fashion Show" = Jojo's Fashion Show
"Magic 3D Coloring Book Cool Critters" = Magic 3D Coloring Book Cool Critters
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"MSMONEYV50" = Microsoft Money 5.0
"NVIDIA Drivers" = NVIDIA Drivers
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"PrintMaster Gold 4.00" = PrintMaster Gold 4.00
"QuickVerse Life Application Bible" = QuickVerse Life Application Bible
"Registry Mechanic_is1" = Registry Mechanic 8.0
"SelectRebatesUninstall" = ShopAtHome.com Toolbar
"Shockwave" = Shockwave
"Shop for HP Supplies" = Shop for HP Supplies
"sp43115" = sp43115
"sp44626" = sp44626
"Spyware Doctor" = Spyware Doctor 7.0
"TomTom HOME" = TomTom HOME 2.6.2.1586
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WildTangent hp Master Uninstall" = My HP Games
"WinSS" = Windows Live OneCare
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Smilebox" = Smilebox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/17/2011 2:02:01 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6053

Error - 2/17/2011 2:02:01 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6053

Error - 2/17/2011 2:02:02 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/17/2011 2:02:02 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7051

Error - 2/17/2011 2:02:02 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7051

Error - 2/17/2011 2:22:26 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/17/2011 2:22:26 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1014

Error - 2/17/2011 2:22:26 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1014

Error - 2/17/2011 2:22:27 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/17/2011 2:22:27 AM | Computer Name = Ream-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2028

[ System Events ]
Error - 3/18/2011 7:45:34 AM | Computer Name = Ream-PC | Source = HTTP | ID = 15021
Description =

Error - 3/18/2011 7:46:59 AM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/18/2011 7:47:23 AM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 3/18/2011 11:13:02 AM | Computer Name = Ream-PC | Source = BROWSER | ID = 8007
Description =

Error - 3/18/2011 11:54:26 AM | Computer Name = Ream-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 10.0.1.2 on the
Network Card with network address 002354A3BF64.

Error - 3/18/2011 2:04:38 PM | Computer Name = Ream-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:51:35 PM on 3/18/2011 was unexpected.

Error - 3/18/2011 2:04:42 PM | Computer Name = Ream-PC | Source = HTTP | ID = 15021
Description =

Error - 3/18/2011 2:06:13 PM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/18/2011 2:06:47 PM | Computer Name = Ream-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 3/18/2011 6:04:39 PM | Computer Name = Ream-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 10.0.1.2 on the
Network Card with network address 002354A3BF64.

[ Windows OneCare Events ]
Error - 2/14/2011 12:06:56 PM | Computer Name = Ream-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x8a190107.

Error - 2/14/2011 7:26:00 PM | Computer Name = Ream-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x8a190107.

Error - 2/16/2011 9:41:54 AM | Computer Name = Ream-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x8a190107.

Error - 2/18/2011 9:45:22 PM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 2/18/2011 9:47:03 PM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/15/2011 4:25:40 PM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:12:17 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:12:58 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:13:39 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb

Error - 3/18/2011 11:14:20 AM | Computer Name = Ream-PC | Source = WinSS | ID = 8009
Description = Machine Aliasing failed with hr = 0x800706bb


< End of report >
I am having some trouble posting the Gmer log. It says you must enter a post. I will try posting just half the log here:

GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-24 22:16:32
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000054 ST325031 rev.3.AH
Running: gmer.exe; Driver: C:\Users\Ream\AppData\Local\Temp\kwldrpoc.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x87463CDC]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x87463ECE]
SSDT \SystemRoot\system32\drivers\TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwTerminateProcess [0x87498BD6]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x874640D6]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 209 868ED98C 8 Bytes [DC, 3C, 46, 87, CE, 3E, 46, …]
.text ntkrnlpa.exe!KeSetEvent + 621 868EDDA4 4 Bytes [D6, 8B, 49, 87] {SALC ; MOV ECX, [ECX-0x79]}
.text ntkrnlpa.exe!KeSetEvent + 6E5 868EDE68 4 Bytes [D6, 40, 46, 87]
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x90C02340, 0x3DA3F7, 0xE8000020]
? \ArcName\multi(0)disk(0)rdisk(0)partition(1)\Windows\system32\drivers\PctWfpFilter.sys The system cannot find the path specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[540] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[540] KERNEL32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[592] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\wininit.exe[592] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\wininit.exe[592] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\wininit.exe[592] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[604] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[604] KERNEL32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\services.exe[640] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[640] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\services.exe[640] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\services.exe[640] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\services.exe[640] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\services.exe[640] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\services.exe[640] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\services.exe[640] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\services.exe[640] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[640] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\services.exe[640] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\services.exe[640] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\services.exe[640] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\services.exe[640] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\services.exe[640] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\services.exe[640] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\services.exe[640] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\services.exe[640] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\services.exe[640] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 7120000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 70A2000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7103000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 70B8000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 70BB000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 709C000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 70D0000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 70D6000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7163000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7099000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 716E000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 70CD000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 7123000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 7130000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 7126000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 70A8000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 70CA000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 712D000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 70EC000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 70D3000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 709F000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 7106000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 70EF000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 70A5000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7100000A
.text C:\Windows\system32\winlogon.exe[664] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 70E5000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 70B5000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7160000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 715A000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 7154000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 70D9000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 70DC000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 7157000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 70DF000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 715D000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 714E000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 7151000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 714B000A
.text C:\Windows\system32\winlogon.exe[664] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 70E2000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [0C, 71] {OR AL, 0x71}
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 70C1000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 70BE000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 70C4000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 70AB000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 70C7000A
.text C:\Windows\system32\winlogon.exe[664] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 70AE000A
.text C:\Windows\system32\winlogon.exe[664] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 70F6000A
.text C:\Windows\system32\winlogon.exe[664] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 70F9000A
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\lsass.exe[684] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\lsass.exe[684] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[684] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\lsass.exe[684] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\lsass.exe[684] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\lsass.exe[684] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\lsm.exe[700] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\lsm.exe[700] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[700] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\lsm.exe[700] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\lsm.exe[700] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\lsm.exe[700] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Program Files\Spyware Doctor\TFEngine\TFService.exe[748] kernel32.dll!CreateRemoteThread + 175 770BCAAA 4 Bytes [00, 00, 6F, 71]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\svchost.exe[840] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[840] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\svchost.exe[840] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\svchost.exe[840] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\svchost.exe[840] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\nvvsvc.exe[888] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Windows\system32\nvvsvc.exe[888] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Windows\system32\nvvsvc.exe[888] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\nvvsvc.exe[888] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1F, 71]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7162000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714D000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 715F000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C5000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7047000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A8000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705D000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7060000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7041000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7075000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7159000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707B000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715C000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7108000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7123000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703E000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710F000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7072000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C8000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D5000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CB000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704D000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706F000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D2000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7091000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7078000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7044000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AB000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7094000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704A000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A5000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708A000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705A000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7105000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FF000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F9000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707E000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7081000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FC000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7084000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7102000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F3000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F6000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F0000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7087000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [11, 71]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7156000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7115000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[916] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B1, 70] {MOV CL, 0x70}
.text C:\Windows\system32\svchost.exe[916] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7066000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7063000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7069000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7050000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706C000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7053000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A
.text C:\Windows\system32\svchost.exe[916] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709B000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A
.text C:\Windows\system32\svchost.exe[916] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70}
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] wininet.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[956] wininet.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [07, 71]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [33, 71]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70AD000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7029000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7090000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 703F000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7042000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7023000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7057000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 705D000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 70F0000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 710B000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7131000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7020000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 70F7000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7054000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70B0000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70BD000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70B3000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 702F000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7051000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70BA000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7073000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 705A000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7026000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 7093000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7076000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 712E000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 702C000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 708D000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Windows\system32\taskeng.exe[1048] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 706C000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 703C000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyExA 76C439AB 4 Bytes [FF, 25, 1E, 00]
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyExA + 5 76C439B0 1 Byte [70]
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70E7000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70E1000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7060000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7063000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70E4000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7066000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70EA000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70DB000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70DE000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70D8000A
.text C:\Windows\system32\taskeng.exe[1048] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7069000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [F9, 70]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7128000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 70FD000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [10, 71]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [99, 70]
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7048000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7045000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712B000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 704B000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7032000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 704E000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7035000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 710E000A
.text C:\Windows\system32\taskeng.exe[1048] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7083000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A
.text C:\Windows\system32\taskeng.exe[1048] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7086000A
.text C:\Windows\system32\taskeng.exe[1048] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 707C000A
.text C:\Windows\system32\taskeng.exe[1048] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7079000A
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1E, 71]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714D000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70BB000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 703D000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 709E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7053000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7056000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7037000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706B000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7071000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7107000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7122000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7034000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7068000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70BE000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70CB000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C1000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7043000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7065000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70C8000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7087000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 706E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703A000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A1000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708A000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7040000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 709B000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7080000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7050000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7104000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F5000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70EF000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7074000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7077000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F2000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707A000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7101000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70E9000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70EC000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E6000A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 707D000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [10, 71]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7114000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A7, 70]
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705C000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7059000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 705F000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7046000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7062000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7049000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A
.text C:\Windows\System32\svchost.exe[1084] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7091000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A
.text C:\Windows\System32\svchost.exe[1084] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7094000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegCreateKeyA
Part 2 of Gmer log: 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Bonjour\mDNSResponder.exe[1120] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70B6000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7038000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7099000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 704E000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7051000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7032000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7066000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 706C000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7103000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 702F000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7063000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70B9000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70C7000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70BC000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 703E000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7060000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70C3000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7082000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7069000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7035000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 709C000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7085000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 703B000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7096000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\System32\svchost.exe[1156] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 707B000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 704B000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7100000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F1000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70EB000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 706F000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7072000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70EE000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7075000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70F4000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70E5000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70E8000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E2000A .text C:\Windows\System32\svchost.exe[1156] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7078000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\System32\svchost.exe[1156] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\System32\svchost.exe[1156] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[1156] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A2, 70] .text C:\Windows\System32\svchost.exe[1156] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7057000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7054000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 705A000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7041000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 705D000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7044000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\System32\svchost.exe[1156] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\System32\svchost.exe[1156] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\System32\svchost.exe[1156] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 708C000A .text C:\Windows\System32\svchost.exe[1156] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\System32\svchost.exe[1156] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\System32\svchost.exe[1156] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\System32\svchost.exe[1156] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 708F000A .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [13, 71] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [33, 71] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714C000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70B6000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7032000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7099000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7048000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 704B000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 702C000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7060000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7066000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7117000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7131000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7029000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7101000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 705D000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70B9000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70C7000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70BC000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7038000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 705A000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70C3000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 707C000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7063000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 702F000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 707F000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7126000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7035000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7096000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713D000A .text C:\Windows\system32\svchost.exe[1184] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7075000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7045000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70EB000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7069000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 706C000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70EE000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 706F000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70E5000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70E8000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E2000A .text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7072000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [05, 71] .text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7120000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7109000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [1C, 71] {SBB AL, 0x71} .text C:\Windows\system32\svchost.exe[1184] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1184] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A2, 70] .text C:\Windows\system32\svchost.exe[1184] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7051000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 704E000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7123000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7054000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 703B000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7057000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 703E000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 711A000A .text C:\Windows\system32\svchost.exe[1184] USER32.dll!EndTask 7576AD32 6 Bytes JMP 7137000A .text C:\Windows\system32\svchost.exe[1184] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7146000A .text C:\Windows\system32\svchost.exe[1184] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 708C000A .text C:\Windows\system32\svchost.exe[1184] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7140000A .text C:\Windows\system32\svchost.exe[1184] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7143000A .text C:\Windows\system32\svchost.exe[1184] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 7149000A .text C:\Windows\system32\svchost.exe[1184] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 708F000A .text C:\Windows\system32\svchost.exe[1184] wininet.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7085000A .text C:\Windows\system32\svchost.exe[1184] wininet.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7082000A .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[1280] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[1280] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[1280] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[1280] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1280] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\svchost.exe[1280] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[1280] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[1280] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[1280] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[1280] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[1280] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[1280] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[1280] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1F, 71] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C4000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7040000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A7000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7056000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7059000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703A000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706E000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7074000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7108000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7123000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7037000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710F000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706B000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C8000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D5000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CB000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7046000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7068000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D2000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708A000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7071000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703D000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AA000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708D000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7043000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A4000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[1348] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7083000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7053000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7105000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FF000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F9000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7077000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707A000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FC000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707D000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7102000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F3000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F6000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F0000A .text C:\Windows\system32\svchost.exe[1348] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7080000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [11, 71] .text C:\Windows\system32\svchost.exe[1348] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7115000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[1348] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1348] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B0, 70] {MOV AL, 0x70} .text C:\Windows\system32\svchost.exe[1348] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705F000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705C000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7062000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7049000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7065000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704C000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[1348] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[1348] shell32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[1348] shell32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709A000A .text C:\Windows\system32\svchost.exe[1348] shell32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[1348] shell32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[1348] shell32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[1348] shell32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709D000A .text C:\Windows\system32\svchost.exe[1348] WinInet.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7093000A .text C:\Windows\system32\svchost.exe[1348] WinInet.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7090000A .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [FA, 70] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [12, 71] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\Explorer.EXE[1380] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7150000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 7128000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 712B000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 714D000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 6F56000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 6E9C000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 6F36000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 6ECE000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 6ED1000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 6E96000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 6EE6000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7137000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 6EEC000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 713C000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 70E0000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 70FE000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7110000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 6E93000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 70E7000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 6EE3000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 6F59000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 6F66000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 6F5C000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [64, 71] .text C:\Windows\Explorer.EXE[1380] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 6EA2000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 6EE0000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 6F63000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 6F02000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 6EE9000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 6E99000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 6F39000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 6F05000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 710D000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 6E9F000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 6F33000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 7119000A .text C:\Windows\Explorer.EXE[1380] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 6EFB000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 6ECB000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 70DD000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70D7000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70D1000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 6EEF000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 6EF2000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70D4000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 6EF5000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70DA000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 6F84000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70CE000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 6F81000A .text C:\Windows\Explorer.EXE[1380] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 6EF8000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7131000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7107000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 712E000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!SetWinEventHook 75729F3A 4 Bytes [FF, 25, 1E, 00] .text C:\Windows\Explorer.EXE[1380] USER32.dll!SetWinEventHook + 5 75729F3F 1 Byte [70] .text C:\Windows\Explorer.EXE[1380] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [03, 71] .text C:\Windows\Explorer.EXE[1380] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\Explorer.EXE[1380] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [3F, 6F] {AAS ; OUTSD } .text C:\Windows\Explorer.EXE[1380] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 6ED7000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 6ED4000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 710A000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 6EDA000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 6EA5000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 6EDD000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 6EC4000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7101000A .text C:\Windows\Explorer.EXE[1380] USER32.dll!EndTask 7576AD32 6 Bytes JMP 7116000A .text C:\Windows\Explorer.EXE[1380] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7122000A .text C:\Windows\Explorer.EXE[1380] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 6F29000A .text C:\Windows\Explorer.EXE[1380] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 711C000A .text C:\Windows\Explorer.EXE[1380] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 711F000A .text C:\Windows\Explorer.EXE[1380] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 7125000A .text C:\Windows\Explorer.EXE[1380] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 6F2C000A .text C:\Windows\Explorer.EXE[1380] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 6F22000A .text C:\Windows\Explorer.EXE[1380] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 6F08000A .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\rundll32.exe[1428] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\rundll32.exe[1428] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\rundll32.exe[1428] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\rundll32.exe[1428] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\rundll32.exe[1428] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\rundll32.exe[1428] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\rundll32.exe[1428] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\rundll32.exe[1428] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\rundll32.exe[1428] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\Dwm.exe[1468] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\Dwm.exe[1468] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\Dwm.exe[1468] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\Dwm.exe[1468] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\Dwm.exe[1468] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\Dwm.exe[1468] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\Dwm.exe[1468] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\Dwm.exe[1468] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\Dwm.exe[1468] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1544] SHELL32.dll!Shell_NotifyIcon
Part 3 of Gmer log: .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70BF000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7041000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A2000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7057000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705A000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703B000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706F000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7075000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7105000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7038000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706C000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C2000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D0000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C5000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7047000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7069000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70CD000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708B000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7072000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703E000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A5000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708E000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7044000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 709F000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[1588] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7084000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7054000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7100000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7078000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707B000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707E000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70FD000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70EE000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EB000A .text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7081000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[1588] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[1588] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1588] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [AB, 70] .text C:\Windows\system32\svchost.exe[1588] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7060000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705D000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7063000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704A000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7066000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704D000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[1588] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[1588] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[1588] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7095000A .text C:\Windows\system32\svchost.exe[1588] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[1588] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[1588] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[1588] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7098000A .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\System32\spoolsv.exe[1744] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\System32\spoolsv.exe[1744] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\System32\spoolsv.exe[1744] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\System32\spoolsv.exe[1744] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\System32\spoolsv.exe[1744] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\System32\spoolsv.exe[1744] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\System32\spoolsv.exe[1744] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\System32\spoolsv.exe[1744] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\System32\spoolsv.exe[1744] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\System32\spoolsv.exe[1744] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 703C000A .text C:\Windows\System32\spoolsv.exe[1744] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7039000A .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70BB000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 703D000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 709E000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7053000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7056000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7037000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706B000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7071000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7104000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7034000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7068000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70BE000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D1000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C1000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7043000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7065000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70CE000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7087000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 706E000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703A000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A1000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708A000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7040000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 709B000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[1768] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7080000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7050000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7101000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FB000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F5000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!AdjustTokenPrivileges
Part 4 of Gmer log .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F8000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707A000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70FE000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70EF000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F2000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EC000A .text C:\Windows\system32\svchost.exe[1768] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 707D000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[1768] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[1768] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[1768] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A7, 70] .text C:\Windows\system32\svchost.exe[1768] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705C000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7059000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 705F000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7046000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7062000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7049000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[1768] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[1768] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[1768] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7091000A .text C:\Windows\system32\svchost.exe[1768] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[1768] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[1768] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[1768] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7094000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1F, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70A3000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7025000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7086000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 703B000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 703E000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 701F000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7053000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7059000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7108000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7123000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 701C000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710F000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7050000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70A6000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70B3000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70A9000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 702B000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 704D000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70B0000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 706F000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7056000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7022000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 7089000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7072000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7028000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7083000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7068000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [11, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7115000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [8F, 70] .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7044000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7041000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7047000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 702E000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 704A000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7031000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7038000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7105000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FF000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F9000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 705C000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 705F000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FC000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7062000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7102000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F3000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F6000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F0000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7065000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7079000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A .text C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[2060] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 707C000A .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\hp\support\hpsysdrv.exe[2096] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\hp\support\hpsysdrv.exe[2096] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\hp\support\hpsysdrv.exe[2096] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\hp\support\hpsysdrv.exe[2096] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\hp\support\hpsysdrv.exe[2096] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\hp\support\hpsysdrv.exe[2096] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\hp\support\hpsysdrv.exe[2096] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\hp\support\hpsysdrv.exe[2096] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\hp\support\hpsysdrv.exe[2096] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\System32\rundll32.exe[2112] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\System32\rundll32.exe[2112] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\System32\rundll32.exe[2112] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\System32\rundll32.exe[2112] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\System32\rundll32.exe[2112] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\System32\rundll32.exe[2112] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\System32\rundll32.exe[2112] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\System32\rundll32.exe[2112] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\System32\rundll32.exe[2112] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\System32\mobsync.exe[2148] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\System32\mobsync.exe[2148] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\System32\mobsync.exe[2148] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\System32\mobsync.exe[2148] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\System32\mobsync.exe[2148] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\System32\mobsync.exe[2148] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\System32\mobsync.exe[2148] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\System32\mobsync.exe[2148] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\System32\mobsync.exe[2148] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[2180] SHELL32.dll!Shell_NotifyIcon
Part 5 of Gmer log .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[2224] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2224] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\svchost.exe[2224] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[2224] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[2224] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[2224] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[2224] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[2224] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[2224] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[2224] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 703C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[2288] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7039000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2336] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1A, 71] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [32, 71] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 7148000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 714B000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 715A000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C0000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A3000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7154000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 7157000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7103000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 711E000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7130000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710A000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C3000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D0000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C6000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70CD000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A6000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 712D000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A0000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 7139000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7100000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FA000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F4000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F7000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70FD000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70EE000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F1000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EB000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [0C, 71] {OR AL, 0x71} .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7151000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7127000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 714E000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7110000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [23, 71] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [AC, 70] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712A000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7121000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] USER32.dll!EndTask 7576AD32 6 Bytes JMP 7136000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7142000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7096000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 713C000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 713F000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 7145000A .text C:\Program Files\Windows Media Player\wmpnetwk.exe[2376] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7099000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A .text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2380] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C5000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7041000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A8000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7057000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7075000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7038000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7047000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7069000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7072000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AB000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7044000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A5000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!WinExec
Part 6 of Gmer log: .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7084000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B1, 70] {MOV CL, 0x70} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7060000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7063000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7066000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7054000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7078000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7081000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7094000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[2436] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7091000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2468] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A .text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[2500] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C4000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7040000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A7000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7056000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7059000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703A000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706E000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7074000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7037000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706B000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C7000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D4000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CA000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7046000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7068000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D1000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708A000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7071000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703D000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AA000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708D000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7043000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A4000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\AirPort\APAgent.exe[2508] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7083000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7053000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FE000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F8000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7077000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707A000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FB000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707D000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F2000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F5000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EF000A .text C:\Program Files\AirPort\APAgent.exe[2508] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7080000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B0, 70] {MOV AL, 0x70} .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705F000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705C000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7062000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7049000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7065000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704C000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\AirPort\APAgent.exe[2508] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\AirPort\APAgent.exe[2508] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\AirPort\APAgent.exe[2508] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709A000A .text C:\Program Files\AirPort\APAgent.exe[2508] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\AirPort\APAgent.exe[2508] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\AirPort\APAgent.exe[2508] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\AirPort\APAgent.exe[2508] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709D000A .text C:\Program Files\AirPort\APAgent.exe[2508] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7093000A .text C:\Program Files\AirPort\APAgent.exe[2508] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7090000A .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708F000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\taskeng.exe[2556] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\taskeng.exe[2556] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\taskeng.exe[2556] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\taskeng.exe[2556] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\taskeng.exe[2556] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\taskeng.exe[2556] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\taskeng.exe[2556] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\taskeng.exe[2556] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\taskeng.exe[2556] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\taskeng.exe[2556] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A .text C:\Windows\system32\taskeng.exe[2556] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1E, 71] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [36, 71] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C3000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 6F95000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A6000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7055000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7058000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 6F8F000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706D000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7073000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7107000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7122000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7134000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 6F8C000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706A000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C7000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D4000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CA000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 6F9B000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7067000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D1000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7089000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7070000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 6F92000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A9000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708C000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7131000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 6F98000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A3000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7082000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7052000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7104000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FE000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F8000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7076000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7079000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FB000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707C000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7101000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F2000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F5000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EF000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 707F000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [10, 71] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712B000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7114000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [27, 71] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [AF, 70] .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705E000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705B000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712E000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7061000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 6F9E000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7064000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 6FA1000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7125000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713A000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7092000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 708F000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7099000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\SelectRebates\SelectRebates.exe[2560] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!OpenProcess
Part 7 of Gmer Log: .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[2588] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[2588] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2588] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\svchost.exe[2588] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[2588] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[2588] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[2588] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[2588] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[2588] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[2588] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[2588] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1F, 71] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C5000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7047000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A8000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705D000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7060000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7041000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7075000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707B000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7108000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7123000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703E000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710F000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7072000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C8000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D5000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CB000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704D000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706F000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D2000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7091000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7078000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7044000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AB000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7094000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704A000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A5000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708A000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [11, 71] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7115000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B1, 70] {MOV CL, 0x70} .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7066000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7063000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7069000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7050000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706C000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7053000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705A000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7105000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FF000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F9000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707E000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7081000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FC000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7084000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7102000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F3000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F6000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F0000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7087000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709B000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A .text C:\Program Files\Registry Mechanic\RMTray.exe[2608] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[2616] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Creative Home\Hallmark Card Studio 2010 Deluxe\Planner\PLNRnote.exe[2676] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2684] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1C, 71] {SBB AL, 0x71} .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [34, 71] {XOR AL, 0x71} .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714D000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70B6000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7032000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7099000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7048000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 704B000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 702C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7060000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7066000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7105000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7120000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7132000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7029000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 705D000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70B9000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70CD000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70BC000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateThread + 1A 770BC928 4 Bytes CALL 0044BC05 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools) .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7038000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 705A000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70C3000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 707C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7063000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 702F000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 709C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 707F000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 712F000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7035000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7096000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713B000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7075000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [0E, 71] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7156000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7129000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7112000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [25, 71] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A2, 70] .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7051000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 704E000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7054000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 703B000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7057000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 703E000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7123000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] USER32.dll!EndTask 7576AD32 6 Bytes JMP 7138000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7045000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7100000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FA000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F4000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7069000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 706C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F7000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 706F000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70FD000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70EB000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70EE000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E8000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7072000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] shell32.dll!ShellExecuteW 75919725 6 Bytes JMP 7146000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] shell32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 708C000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] shell32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7140000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] shell32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7143000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] shell32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 7149000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] shell32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 708F000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] wininet.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7085000A .text C:\Program Files\Spyware Doctor\pctsSvc.exe[2728] wininet.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7082000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1F, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [37, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7162000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7150000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 715F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C5000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7047000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A8000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7060000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7041000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7075000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7159000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7108000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7123000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7135000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7072000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C8000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D5000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CB000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D2000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7091000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7078000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7044000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AB000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7094000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7132000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A5000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7105000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FF000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7081000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7084000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7102000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F3000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F0000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7087000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [11, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7156000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7153000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7115000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [28, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B1, 70] {MOV CL, 0x70} .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7066000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7063000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7069000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7050000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7053000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7126000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 703B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2740] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7038000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1E, 71] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C4000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7040000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A7000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7056000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7059000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703A000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706E000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7074000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7107000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7122000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7037000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706B000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C7000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D4000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CA000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7046000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7068000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D1000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708A000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7071000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703D000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AA000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708D000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7043000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A4000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7083000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7053000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7104000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FE000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F8000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7077000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707A000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FB000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707D000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7101000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F2000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F5000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EF000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7080000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [10, 71] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712B000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7114000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [27, 71] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B0, 70] {MOV AL, 0x70} .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705F000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705C000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712E000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7062000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7049000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7065000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704C000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7125000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709A000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709D000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7093000A .text C:\Windows\WindowsMobile\wmdSync.exe[2752] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7090000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [18, 71] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [36, 71] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7162000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714C000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 714F000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 715F000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70BE000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 6F6D000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A1000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 6F83000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7053000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 6F67000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7068000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7159000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 706E000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715C000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7101000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 711C000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7131000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 6F64000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7108000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7065000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C1000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70CE000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C4000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 6F73000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7062000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70CB000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7084000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 706B000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 6F6A000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A4000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7087000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 712E000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 6F70000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 709E000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713D000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 707D000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 6F80000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 70FE000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F8000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F2000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7071000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7074000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F5000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7077000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70FB000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70EC000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70EF000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E9000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 707A000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [0A, 71] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7156000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7125000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7152000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 710E000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [21, 71] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [AA, 70] .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7059000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7056000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712B000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 705C000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 6F76000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 705F000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 6F79000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 711F000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713A000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7146000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7094000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7140000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7143000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 7149000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7097000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 708D000A .text C:\Program Files\Windows Sidebar\sidebar.exe[2760] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 708A000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Windows Media Player\wmpnscfg.exe[2768] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1E, 71] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C4000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7046000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A7000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705C000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705F000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7040000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7074000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707A000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7107000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7122000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703D000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710E000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7071000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C7000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D4000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CA000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704C000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706E000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D1000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7090000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7077000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7043000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AA000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7093000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7049000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A4000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[2776] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7089000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7059000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7104000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FE000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F8000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707D000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7080000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FB000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7083000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7101000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F2000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F5000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EF000A .text C:\Windows\system32\svchost.exe[2776] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7086000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [10, 71] .text C:\Windows\system32\svchost.exe[2776] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712B000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7114000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [27, 71] .text C:\Windows\system32\svchost.exe[2776] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[2776] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B0, 70] {MOV AL, 0x70} .text C:\Windows\system32\svchost.exe[2776] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7065000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7062000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712E000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7068000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704F000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706B000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7052000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7125000A .text C:\Windows\system32\svchost.exe[2776] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[2776] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[2776] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709A000A .text C:\Windows\system32\svchost.exe[2776] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[2776] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[2776] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[2776] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709D000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] KERNEL32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe[2872] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7042000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7058000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7070000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7076000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7039000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7048000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706A000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7073000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CreateDirectoryA
Part 7 of Gmer log: .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7045000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7085000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7061000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7064000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7067000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704E000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7055000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7079000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7082000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7095000A .text C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac[2936] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7092000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [1D, 71] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [35, 71] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C3000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7045000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A6000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705B000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 705E000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703F000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7073000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7079000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7106000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7121000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7133000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703C000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 710D000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7070000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C6000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D3000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C9000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateThread + 1A 770BC928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704B000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706D000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D0000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708F000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7076000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7042000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A9000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7092000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7130000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7048000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A3000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713E000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7088000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [0F, 71] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712A000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7113000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [26, 71] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [AF, 70] .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7064000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7061000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 712D000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7067000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 704E000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706A000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7051000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7124000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] USER32.dll!EndTask 7576AD32 6 Bytes JMP 7139000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7058000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7103000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FD000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F7000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707C000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707F000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FA000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7082000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7100000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F1000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F4000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EE000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7085000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] shell32.dll!ShellExecuteW 75919725 6 Bytes JMP 7147000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] shell32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7099000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] shell32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7141000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] shell32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7144000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] shell32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714A000A .text C:\Program Files\Spyware Doctor\pctsTray.exe[2980] shell32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C5000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7047000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A8000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705D000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7060000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7041000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7075000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707B000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703E000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7072000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C8000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D5000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CB000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704D000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 706F000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D2000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7091000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7078000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7044000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AB000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7094000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704A000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A5000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[3024] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708A000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705A000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707E000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7081000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7084000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[3024] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7087000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[3024] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[3024] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[3024] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B1, 70] {MOV CL, 0x70} .text C:\Windows\system32\svchost.exe[3024] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7066000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7063000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7069000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7050000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706C000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7053000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[3024] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[3024] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[3024] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709B000A .text C:\Windows\system32\svchost.exe[3024] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[3024] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[3024] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[3024] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709E000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] shell32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] shell32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] shell32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] shell32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] shell32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Spyware Doctor\upgrade.exe[3048] shell32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[3056] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\System32\svchost.exe[3092] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\System32\svchost.exe[3092] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\System32\svchost.exe[3092] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\System32\svchost.exe[3092] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3092] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\System32\svchost.exe[3092] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\System32\svchost.exe[3092] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\System32\svchost.exe[3092] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\System32\svchost.exe[3092] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\System32\svchost.exe[3092] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\System32\svchost.exe[3092] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\System32\svchost.exe[3092] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\System32\svchost.exe[3092] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [13, 71] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [2B, 71] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 7042000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 6FC4000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 7025000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 6FDA000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 6FDD000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 6FBE000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 6FF2000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 6FF8000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 70F9000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7117000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7129000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 6FBB000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7101000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 6FEF000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 7045000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70C6000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 7048000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 6FCA000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 6FEC000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 704F000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 700E000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 6FF5000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 6FC1000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 7028000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7011000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7126000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 6FC7000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 7022000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 7132000A .text C:\Windows\system32\SearchIndexer.exe[3144] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7007000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 6FD7000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 70F6000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F0000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70EA000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 6FFB000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 6FFE000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegCreateKeyW 76C5391E 4 Bytes [FF, 25, 1E, 00] .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegCreateKeyW + 5 76C53923 1 Byte [70] .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7001000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70F3000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70E4000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70E7000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E1000A .text C:\Windows\system32\SearchIndexer.exe[3144] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7004000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [05, 71] .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7120000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7109000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [1C, 71] {SBB AL, 0x71} .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [2E, 70] .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 6FE3000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 6FE0000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7123000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 6FE6000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 6FCD000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 6FE9000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 6FD0000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 711A000A .text C:\Windows\system32\SearchIndexer.exe[3144] USER32.dll!EndTask 7576AD32 6 Bytes JMP 712F000A .text C:\Windows\system32\SearchIndexer.exe[3144] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 713B000A .text C:\Windows\system32\SearchIndexer.exe[3144] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7018000A .text C:\Windows\system32\SearchIndexer.exe[3144] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7135000A .text C:\Windows\system32\SearchIndexer.exe[3144] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7138000A .text C:\Windows\system32\SearchIndexer.exe[3144] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\SearchIndexer.exe[3144] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 701B000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\DRIVERS\xaudio.exe[3208] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[3276] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [15, 71] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [2D, 71] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 715E000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 7143000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7146000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 715B000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70BB000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 703D000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 709E000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7053000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7056000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7037000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706B000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 7155000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7071000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 7158000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!GetVolumeInformationW
Part 9 of Gmer log: .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7119000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 712B000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7034000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7105000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7068000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70BE000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70CB000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70C1000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7043000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7065000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70C8000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7087000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 706E000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703A000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70A1000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708A000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7128000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7040000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 709B000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 7134000A .text C:\Windows\system32\WUDFHost.exe[3308] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7080000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7050000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 70FB000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70F5000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70EF000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7074000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7077000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70F2000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707A000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 70F8000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70E9000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70EC000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70E6000A .text C:\Windows\system32\WUDFHost.exe[3308] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 707D000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [07, 71] .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 714C000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 7122000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7149000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 710B000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [1E, 71] .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [A7, 70] .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705C000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7059000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7125000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 705F000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7046000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7062000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7049000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 711C000A .text C:\Windows\system32\WUDFHost.exe[3308] USER32.dll!EndTask 7576AD32 6 Bytes JMP 7131000A .text C:\Windows\system32\WUDFHost.exe[3308] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 713D000A .text C:\Windows\system32\WUDFHost.exe[3308] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 7091000A .text C:\Windows\system32\WUDFHost.exe[3308] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7137000A .text C:\Windows\system32\WUDFHost.exe[3308] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 713A000A .text C:\Windows\system32\WUDFHost.exe[3308] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 7140000A .text C:\Windows\system32\WUDFHost.exe[3308] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 7094000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C4000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7040000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A7000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 7056000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7059000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 703A000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 706E000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 7074000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 7037000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 706B000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C7000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D4000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CA000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 7046000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7068000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D1000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 708A000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7071000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 703D000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AA000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 708D000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 7043000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A4000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 7083000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 7053000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 70FE000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70F8000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 7077000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 707A000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FB000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 707D000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7101000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F2000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F5000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70EF000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7080000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B0, 70] {MOV AL, 0x70} .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 705F000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 705C000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 7062000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7049000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 7065000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 704C000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709A000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709D000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] WININET.dll!InternetOpenUrlA 7670F3A4 6 Bytes JMP 7093000A .text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[3344] WININET.dll!InternetOpenUrlW 76756D77 6 Bytes JMP 7090000A .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\System32\svchost.exe[3840] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\System32\svchost.exe[3840] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\System32\svchost.exe[3840] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\System32\svchost.exe[3840] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\System32\svchost.exe[3840] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\System32\svchost.exe[3840] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\System32\svchost.exe[3840] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\System32\svchost.exe[3840] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\System32\svchost.exe[3840] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\System32\svchost.exe[3840] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\System32\svchost.exe[3840] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\System32\svchost.exe[3840] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\System32\svchost.exe[3840] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\wuauclt.exe[3964] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\wuauclt.exe[3964] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\wuauclt.exe[3964] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\wuauclt.exe[3964] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\wuauclt.exe[3964] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\wuauclt.exe[3964] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\wuauclt.exe[3964] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\wuauclt.exe[3964] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\wuauclt.exe[3964] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\svchost.exe[4164] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\svchost.exe[4164] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\svchost.exe[4164] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\svchost.exe[4164] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\svchost.exe[4164] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\svchost.exe[4164] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\svchost.exe[4164] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\svchost.exe[4164] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\svchost.exe[4164] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\svchost.exe[4164] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\svchost.exe[4164] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\svchost.exe[4164] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\svchost.exe[4164] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!WinExec
Oops! that last one was part 8, this is part 9 of Gmer log: .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] KERNEL32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4588] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\PROGRA~1\MICROS~2\wkcalrem.exe[4888] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Windows\system32\wbem\wmiprvse.exe[5420] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[5484] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[5564] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtClose 76F54164 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtClose + 4 76F54168 2 Bytes [35, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateFile 76F54224 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateFile + 4 76F54228 2 Bytes [17, 5F] {POP SS; POP EDI} .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateKey 76F54264 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateKey + 4 76F54268 2 Bytes [05, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateProcess 76F542E4 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateProcess + 4 76F542E8 2 Bytes [29, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateProcessEx 76F542F4 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateProcessEx + 4 76F542F8 2 Bytes [2C, 5F] {SUB AL, 0x5f} .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateSection 76F54314 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateSection + 4 76F54318 2 Bytes [23, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtDeleteKey 76F54614 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtDeleteKey + 4 76F54618 2 Bytes [0B, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtDeleteValueKey 76F54644 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtDeleteValueKey + 4 76F54648 2 Bytes [11, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtLoadDriver 76F548B4 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtLoadDriver + 4 76F548B8 2 Bytes [20, 71] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtRenameKey 76F54F14 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtRenameKey + 4 76F54F18 2 Bytes [14, 5F] {ADC AL, 0x5f} .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtSetInformationFile 76F55134 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtSetInformationFile + 4 76F55138 2 Bytes [20, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtSetValueKey 76F552A4 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtSetValueKey + 4 76F552A8 2 Bytes [0E, 5F] {PUSH CS; POP EDI} .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtSuspendProcess 76F55304 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtSuspendProcess + 4 76F55308 2 Bytes [38, 71] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtTerminateProcess 76F55344 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtTerminateProcess + 4 76F55348 2 Bytes [2F, 5F] {DAS ; POP EDI} .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtWriteFile 76F55494 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtWriteFile + 4 76F55498 2 Bytes [1A, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtWriteFileGather 76F554A4 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtWriteFileGather + 4 76F554A8 2 Bytes [1D, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtWriteVirtualMemory 76F554C4 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtWriteVirtualMemory + 4 76F554C8 2 Bytes [32, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateUserProcess 76F55654 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] ntdll.dll!NtCreateUserProcess + 4 76F55658 2 Bytes [26, 5F] .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!TerminateProcess 770718EF 6 Bytes JMP 7163000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateProcessW 77071BF3 6 Bytes JMP 714E000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateProcessA 77071C28 6 Bytes JMP 7151000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!WriteProcessMemory 77071CB8 6 Bytes JMP 7160000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!VirtualProtect 77071DC3 6 Bytes JMP 70C6000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!MoveFileW 7707A2F2 6 Bytes JMP 7048000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CopyFileW 77080299 6 Bytes JMP 70A9000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!DeleteFileW 7708F4B6 6 Bytes JMP 705E000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!DeleteFileA 7708F5D2 6 Bytes JMP 7061000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!MoveFileExW 770910C8 6 Bytes JMP 7042000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!OpenMutexA 770933F7 6 Bytes JMP 7076000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!LoadLibraryExW 77099109 6 Bytes JMP 5F070F5A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!LoadLibraryW 77099362 6 Bytes JMP 715A000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateMutexA 77099431 6 Bytes JMP 707C000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!LoadLibraryA 770994DC 6 Bytes JMP 715D000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!GetVolumeInformationW 7709D7FE 6 Bytes JMP 7109000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!VirtualProtectEx 7709DBDA 6 Bytes JMP 7124000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!TerminateThread 770B41F7 6 Bytes JMP 7136000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!OpenProcess 770B7267 6 Bytes JMP 703F000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!GetProcAddress 770B903B 6 Bytes JMP 7110000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!OpenMutexW 770BAA85 6 Bytes JMP 7073000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!VirtualAlloc 770BAD55 6 Bytes JMP 70C9000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateFileW 770BAECB 6 Bytes JMP 70D6000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateThread 770BC90E 6 Bytes JMP 70CC000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateRemoteThread 770BC935 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateRemoteThread + 4 770BC939 2 Bytes [6D, 71] .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!WideCharToMultiByte 770BCBF8 6 Bytes JMP 704E000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!MultiByteToWideChar 770BCCDB 6 Bytes JMP 7070000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateFileA 770BCE5F 6 Bytes JMP 70D3000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateDirectoryW 770BD166 6 Bytes JMP 7092000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateMutexW 770BD555 6 Bytes JMP 7079000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!MoveFileExA 770C0F0A 6 Bytes JMP 7045000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CopyFileA 770C2433 6 Bytes JMP 70AC000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CreateDirectoryA 770C70F4 6 Bytes JMP 7095000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!DebugActiveProcess 770F9A61 6 Bytes JMP 7133000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!MoveFileA 770FF641 6 Bytes JMP 704B000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!CopyFileExA 771019F9 6 Bytes JMP 70A6000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!WinExec 77105CF7 6 Bytes JMP 713F000A .text C:\Users\Ream\Desktop\gmer.exe[5604] kernel32.dll!SetThreadContext 7710794A 6 Bytes JMP 708B000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!RegisterRawInputDevices 75726161 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!RegisterRawInputDevices + 4 75726165 2 Bytes [12, 71] .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!SetWindowsHookExA 75726322 6 Bytes JMP 7157000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!GetAsyncKeyState 7572863C 6 Bytes JMP 712D000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!SetWindowsHookExW 757287AD 6 Bytes JMP 7154000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!SetWinEventHook 75729F3A 6 Bytes JMP 7116000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!GetKeyboardState 7572BD7D 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!GetKeyboardState + 4 7572BD81 2 Bytes [29, 71] .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!ShowWindow 7572CA10 3 Bytes [FF, 25, 1E] .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!ShowWindow + 4 7572CA14 2 Bytes [B2, 70] {MOV DL, 0x70} .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!CreateWindowExA 7572DC2A 6 Bytes JMP 7067000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!CreateWindowExW 75731305 6 Bytes JMP 7064000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!GetKeyState 75738CB1 6 Bytes JMP 7130000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!DrawTextW 757397D3 6 Bytes JMP 706A000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!SetWindowTextW 75739815 6 Bytes JMP 7051000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!DrawTextA 7574558D 6 Bytes JMP 706D000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!SetWindowTextA 7574A4E6 6 Bytes JMP 7054000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!DdeConnect 75769A1F 6 Bytes JMP 7127000A .text C:\Users\Ream\Desktop\gmer.exe[5604] USER32.dll!EndTask 7576AD32 6 Bytes JMP 713C000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegDeleteKeyA 76C41C8C 6 Bytes JMP 705B000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegCreateKeyExA 76C439AB 6 Bytes JMP 7106000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegCreateKeyA 76C43BA9 6 Bytes JMP 7100000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegOpenKeyA 76C489C7 6 Bytes JMP 70FA000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!AdjustTokenPrivileges 76C499CD 6 Bytes JMP 707F000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!LookupPrivilegeValueW 76C536FF 6 Bytes JMP 7082000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegCreateKeyW 76C5391E 6 Bytes JMP 70FD000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!LookupPrivilegeValueA 76C53A0F 6 Bytes JMP 7085000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegCreateKeyExW 76C541F1 6 Bytes JMP 7103000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegOpenKeyExA 76C57C42 6 Bytes JMP 70F4000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegOpenKeyW 76C5E2B5 6 Bytes JMP 70F7000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!RegOpenKeyExW 76C67BA1 6 Bytes JMP 70F1000A .text C:\Users\Ream\Desktop\gmer.exe[5604] ADVAPI32.dll!OpenProcessToken 76C67DDC 6 Bytes JMP 7088000A .text C:\Users\Ream\Desktop\gmer.exe[5604] SHELL32.dll!ShellExecuteW 75919725 6 Bytes JMP 7148000A .text C:\Users\Ream\Desktop\gmer.exe[5604] SHELL32.dll!Shell_NotifyIconW 75958642 6 Bytes JMP 709C000A .text C:\Users\Ream\Desktop\gmer.exe[5604] SHELL32.dll!ShellExecuteExW 7596C155 6 Bytes JMP 7142000A .text C:\Users\Ream\Desktop\gmer.exe[5604] SHELL32.dll!ShellExecuteEx 75B1A292 6 Bytes JMP 7145000A .text C:\Users\Ream\Desktop\gmer.exe[5604] SHELL32.dll!ShellExecuteA 75B1A32D 6 Bytes JMP 714B000A .text C:\Users\Ream\Desktop\gmer.exe[5604] SHELL32.dll!Shell_NotifyIcon 75B1BAED 6 Bytes JMP 709F000A —- Devices - GMER 1.0.15 —- AttachedDevice \FileSystem\Ntfs \Ntfs TfFsMon.sys (ThreatFire Filesystem Monitor/PC Tools) AttachedDevice \Driver\tdx \Device\Tcp pctgntdi.sys Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys —- EOF - GMER 1.0.15 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI