This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hotmail Probs

71 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am a bit of a computer dummy but it seems I have some kind of a virus as my hotmail has sent out a number of e-mails to my address book contacts offering herbal viagra.

I have Zone alarm as my firewall and avast as the anti virus.

Computer uses WINDOWS VISTA its a Cyberpower make with Intel Quad core Q6600 2.4GHZ 4CG RAm 32 Bit Op sys.

I have run HiJAck this and posted the log below as you suggest.

Thank you for your help.

Andrew

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:02:01, on 23/08/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZPAJR1Q\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab99160.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

–
End of file - 10698 bytes
Hello ANDREW1959 and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Before we run any system scans the first thing you need to do is to go to a different machine and change your hotmail login password as it may have been compromised.

Once you have changed your password please proceed as follows:


  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Right click on the DDS icon and select "Run as Administrator" to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click on GMER.exe and select "Run as Administrator" to run the program. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



Please post both DDS logs and the GMER log in your next reply. If you encounter any problems with the scans just let me know :)

Are there any other symptoms being displayed by your machine besides the unwanted e mails (error messages, popups, redirects etc)?
Hi Jon Tom and thank you for the help you are giving me. I am posting the 2 DDS logs in this reply and will post the GMER separately. . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 12:30:27 on 2011-08-23 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1556 [GMT 1:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WUDFHost.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\ZoneLabs\vsmon.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe C:\Windows\System32\rundll32.exe C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.co.uk/ uInternet Settings,ProxyOverride = *.local uURLSearchHooks: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll mURLSearchHooks: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll mURLSearchHooks: H - No File BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll TB: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Google Update] "c:\users\administrator\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe mRun: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab99160.cab DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-gb.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{E6592E60-941E-4529-BA68-457CEAB639C1} : DhcpNameServer = 192.168.0.1 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\administrator\appdata\roaming\mozilla\firefox\profiles\bhwd8ppd.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo! FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\nos\bin\np_gp.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\administrator\appdata\local\google\update\1.3.21.57\npGoogleUpdate3.dll FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: ZoneAlarm Security Engine: {FFB96CC1-7EB3-449D-B827-DB661701C6BB} - c:\program files\checkpoint\zaforcefield\TrustChecker FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: avast! WebRep: [removed] - c:\program files\avast software\avast\webrep\FF FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-11 441176] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-11 309848] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R1 MpKsl5877a292;MpKsl5877a292;c:\programdata\microsoft\microsoft antimalware\definition updates\{8189663f-16c8-4540-ab1c-363d9d3d1308}\MpKsl5877a292.sys [2011-8-23 28752] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-11 19544] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-4-11 54104] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-11 42184] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2009-10-14 26352] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2009-10-14 493032] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-4-11 1153368] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944] R3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2009-5-6 413208] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-5-3 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-5-3 79360] S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\common files\creative labs shared\service\MT6Licensing.exe [2010-5-3 79360] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-26 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2011-5-13 1492840] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2008-1-21 21504] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] . =============== Created Last 30 ================ . 2011-08-23 11:07:53 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8189663f-16c8-4540-ab1c-363d9d3d1308}\MpKsl5877a292.sys 2011-08-23 06:46:36 7152464 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8189663f-16c8-4540-ab1c-363d9d3d1308}\mpengine.dll 2011-08-23 06:38:11 ——– d—–w- c:\users\administrator\appdata\local\{BB1C604F-80D9-4BEF-8D01-1FBE98F07DC1} 2011-08-23 06:37:31 ——– d—–w- c:\users\administrator\appdata\local\{BB6634D5-56EE-4E34-AD4E-57819243E4A2} 2011-08-22 18:19:26 ——– d—–w- c:\users\administrator\appdata\local\{DD577ECC-C74C-4DA0-A50F-B7E775D7A098} 2011-08-22 18:18:44 ——– d—–w- c:\users\administrator\appdata\local\{BE38B40B-7201-4981-84FA-A142ED643B8D} 2011-08-22 16:04:38 ——– d—–w- c:\users\administrator\appdata\roaming\My Battle for Middle-earth™ II Files 2011-08-22 15:38:25 51472 —-a-w- c:\program files\microsoft games\age of empires online\rmdll\final\RandomMap.dll 2011-08-22 15:38:25 19216 —-a-w- c:\program files\microsoft games\age of empires online\rmdll\final\CLRBinder.dll 2011-08-22 15:38:25 13584 —-a-w- c:\program files\microsoft games\age of empires online\rmdll\final\RandomMapBinder.dll 2011-08-22 15:27:27 81998 —-a-w- c:\program files\microsoft games\age of empires online\RockallDLL.dll 2011-08-22 15:27:27 746496 —-a-w- c:\program files\microsoft games\age of empires online\granny2.dll 2011-08-22 15:27:25 139536 —-a-w- c:\program files\microsoft games\age of empires online\eulax.dll 2011-08-22 15:27:24 173408 —-a-w- c:\program files\microsoft games\age of empires online\pw32b.dll 2011-08-22 15:17:24 452440 —-a-w- c:\windows\system32\d3dx10_40.dll 2011-08-22 15:17:24 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll 2011-08-22 15:17:24 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll 2011-08-22 15:16:47 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll 2011-08-22 15:16:46 81768 —-a-w- c:\windows\system32\xinput1_3.dll 2011-08-22 15:16:04 ——– d—–w- c:\windows\system32\xlive 2011-08-22 15:15:57 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE 2011-08-22 06:18:11 ——– d—–w- c:\users\administrator\appdata\local\{7DEFB71C-E2A7-4D11-9123-F4527E95F954} 2011-08-22 06:17:10 ——– d—–w- c:\users\administrator\appdata\local\{A4A3443F-5177-411C-A090-542205BB2EDC} 2011-08-20 20:19:26 ——– d—–w- c:\users\administrator\appdata\local\{6E15B582-69C4-4947-A0BA-A887090C0BDB} 2011-08-20 20:19:22 ——– d—–w- c:\users\administrator\appdata\local\{1A42ADFB-37CE-41B2-BB08-3178967AB59D} 2011-08-20 08:19:01 ——– d—–w- c:\users\administrator\appdata\local\{EB9B4C8A-4926-4002-84CD-DE3CA9404A7F} 2011-08-20 08:18:22 ——– d—–w- c:\users\administrator\appdata\local\{0E1D300C-B947-4A4A-98D9-67C884F9FDB6} 2011-08-19 07:13:23 ——– d—–w- c:\users\administrator\appdata\local\{DBAF15B4-DC32-4547-B37E-44E1AC15478B} 2011-08-19 07:12:48 ——– d—–w- c:\users\administrator\appdata\local\{84511C73-5352-4661-AB3C-ADBAD56F2326} 2011-08-18 18:43:40 ——– d—–w- c:\users\administrator\appdata\local\{A0D4AE99-992C-49ED-867D-CA34DF2C280A} 2011-08-18 18:43:07 ——– d—–w- c:\users\administrator\appdata\local\{F06E26C6-106D-429B-B548-CDA072FE2F8E} 2011-08-18 06:42:47 ——– d—–w- c:\users\administrator\appdata\local\{9CED5CEF-31FA-4A9C-8D86-91C2EDDAE775} 2011-08-18 06:42:08 ——– d—–w- c:\users\administrator\appdata\local\{8DE2A289-DC09-436B-8F8A-C1A65C6AF932} 2011-08-17 06:44:58 ——– d—–w- c:\users\administrator\appdata\local\{59DC2B69-7799-40D5-8029-FC632E06F0DC} 2011-08-17 06:44:23 ——– d—–w- c:\users\administrator\appdata\local\{A3F5645A-BE09-4EFD-81AC-A60EDA12BA79} 2011-08-16 07:37:38 ——– d—–w- c:\users\administrator\appdata\local\{AAB23CB2-F8D0-4F11-92F7-0EF5183AD851} 2011-08-16 07:37:33 ——– d—–w- c:\users\administrator\appdata\local\{A0F48B9A-9AD5-4490-9DF3-5EA7B54853F2} 2011-08-15 22:32:57 ——– d—–w- c:\users\administrator\appdata\local\{4E355750-C353-4B59-9114-9C44AF6148C3} 2011-08-15 22:32:08 ——– d—–w- c:\users\administrator\appdata\local\{483749DD-C772-4806-A489-EAE57405F568} 2011-08-15 08:37:58 ——– d—–w- c:\users\administrator\appdata\local\{57B0045C-418F-4066-8952-8F5D63DC5B51} 2011-08-15 08:37:53 ——– d—–w- c:\users\administrator\appdata\local\{7B66514C-8BDD-406B-82C4-21F6ACF39DBB} 2011-08-14 20:37:32 ——– d—–w- c:\users\administrator\appdata\local\{749BE988-E587-44B2-A28E-75FDAB3311E9} 2011-08-14 20:36:51 ——– d—–w- c:\users\administrator\appdata\local\{8A2A1527-00EC-4D17-9D3A-44F4617AA280} 2011-08-14 07:32:28 ——– d—–w- c:\users\administrator\appdata\local\{05D69155-DD53-4CD4-B436-42F196C82807} 2011-08-14 07:32:24 ——– d—–w- c:\users\administrator\appdata\local\{88DC7082-0688-496D-AA5B-777BCC3EA95C} 2011-08-13 12:03:52 ——– d—–w- c:\users\administrator\appdata\local\{56887BED-7B7B-4AA1-B294-91B76B1819AF} 2011-08-13 12:03:17 ——– d—–w- c:\users\administrator\appdata\local\{C0317D4A-883E-458F-8D82-FD18CC961BE4} 2011-08-12 22:02:56 ——– d—–w- c:\users\administrator\appdata\local\{A1375CD1-EF92-44C0-BA70-2059C3DBA914} 2011-08-12 22:02:52 ——– d—–w- c:\users\administrator\appdata\local\{8BC83B3B-2670-454A-929D-4FDCFB3F586A} 2011-08-12 10:02:47 ——– d—–w- c:\users\administrator\appdata\local\{D8BDD23A-CAA5-4CF9-8D6B-7AD1E563954F} 2011-08-12 10:02:20 ——– d—–w- c:\users\administrator\appdata\local\{F0259A1C-815D-4AB0-8EEE-F0DEEA6658C5} 2011-08-11 22:01:59 ——– d—–w- c:\users\administrator\appdata\local\{957782BA-ECE3-4D21-B17E-D9EDC89B919D} 2011-08-11 22:01:29 ——– d—–w- c:\users\administrator\appdata\local\{32CE3A8D-2DFE-43E7-BD8C-29CF96E7747F} 2011-08-11 11:35:19 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{3a8fca32-419f-40c1-8cb2-9991abe99254}\gapaengine.dll 2011-08-11 10:01:08 ——– d—–w- c:\users\administrator\appdata\local\{0EB86DE2-B469-43ED-BC2E-B476BBB2CDCE} 2011-08-11 10:01:03 ——– d—–w- c:\users\administrator\appdata\local\{FB693ED0-23F5-4DC7-A507-7AC56E93E3D2} 2011-08-10 21:25:41 ——– d—–w- c:\users\administrator\appdata\local\{0590E4B2-19F2-4B58-873A-4935DF7D63F0} 2011-08-10 21:25:37 ——– d—–w- c:\users\administrator\appdata\local\{A8DF8092-0A37-44BC-9CA8-4449AC7F86A8} 2011-08-10 09:40:36 375808 —-a-w- c:\windows\system32\winsrv.dll 2011-08-10 09:40:32 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-08-10 09:40:27 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-08-10 09:40:16 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-10 09:40:15 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-10 09:40:13 913296 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-08-10 09:40:13 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2011-08-10 09:28:58 6881616 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\updates\mpengine.dll 2011-08-10 09:25:11 ——– d—–w- c:\users\administrator\appdata\local\{7140477B-98A2-4709-A986-ECB14C8118C1} 2011-08-10 09:24:38 ——– d—–w- c:\users\administrator\appdata\local\{AD4955EC-93FF-4BEA-B2FF-83666209B8BC} 2011-08-09 12:36:54 ——– d—–w- c:\users\administrator\appdata\local\{50C4B87E-7029-4166-81F0-9D976AD13DEF} 2011-08-09 12:36:49 ——– d—–w- c:\users\administrator\appdata\local\{9175BBA0-56D8-4457-846E-DAE0B4F3F3AA} 2011-08-09 09:58:08 ——– d—–w- c:\windows\en 2011-08-09 09:52:06 15712 —-a-w- c:\program files\common files\windows live\.cache\ffb8746e1cc567902\MeshBetaRemover.exe 2011-08-09 09:47:53 ——– d—–w- c:\users\administrator\appdata\local\{679300A6-05CD-4235-8EE9-BBD294623509} 2011-08-09 09:47:49 ——– d—–w- c:\users\administrator\appdata\local\{FE511940-9798-4DDA-BA03-225AE65164E9} 2011-08-09 08:35:24 ——– d—–w- c:\users\administrator\appdata\local\{FC528296-6101-4834-8491-A97A2DC8486A} 2011-08-09 08:35:20 ——– d—–w- c:\users\administrator\appdata\local\{60656F51-2216-4EC5-B0CF-37C8072D5C1B} 2011-08-08 20:04:26 ——– d—–w- c:\users\administrator\appdata\local\{C0474FA6-56C9-468D-ABFF-203403E25036} 2011-08-08 20:04:18 ——– d—–w- c:\users\administrator\appdata\local\{C49FC844-48E5-4480-A351-B424486F7EEE} 2011-08-08 08:54:35 ——– d—–w- c:\users\administrator\appdata\local\{4F070646-E214-491A-9ED3-E0D48F37757E} 2011-08-08 08:54:21 ——– d—–w- c:\users\administrator\appdata\local\{CAAEC758-835D-4DD4-8E89-B0A5F455971A} 2011-08-07 12:05:05 ——– d—–w- c:\users\administrator\appdata\local\{6719D84D-6785-4AD6-9592-0635D1773D5A} 2011-08-07 12:05:01 ——– d—–w- c:\users\administrator\appdata\local\{B36E0131-0F2B-405C-A7E9-AC9E4D6176C0} 2011-08-07 10:00:56 ——– d—–w- c:\users\administrator\appdata\local\{8B547D1F-DA5E-4387-BFEE-D6EA3D0B795D} 2011-08-07 10:00:48 ——– d—–w- c:\users\administrator\appdata\local\{113302E7-D0F0-4C3C-BBD0-12D55359211E} 2011-08-07 08:21:40 ——– d—–w- c:\users\administrator\appdata\local\{1F5A40A8-2B4A-4802-B3CC-1A856A99A522} 2011-08-07 08:21:13 ——– d—–w- c:\users\administrator\appdata\local\{1CA762B6-97DA-46A5-B715-1A5331B127E1} 2011-08-07 01:37:19 ——– d—–w- c:\users\administrator\appdata\local\{B050B989-58D3-425F-8271-08805AF03E7E} 2011-08-07 01:37:15 ——– d—–w- c:\users\administrator\appdata\local\{48C4EF7B-766F-4574-AE94-6F7D842E5061} 2011-08-06 12:20:24 ——– d—–w- c:\users\administrator\appdata\local\{6C482C72-9737-491A-9ECD-72EA4E6C5742} 2011-08-06 12:19:44 ——– d—–w- c:\users\administrator\appdata\local\{B47590D5-D425-483D-9444-740A34D111F7} 2011-08-06 11:48:21 ——– d—–w- c:\users\administrator\appdata\local\{4E958182-98BC-4A8F-9A9D-992AA1B9BBEE} 2011-08-06 11:48:17 ——– d—–w- c:\users\administrator\appdata\local\{DB5DF2BF-4DE7-4B24-A7A8-BF70C581E504} 2011-08-06 07:25:53 ——– d—–w- c:\users\administrator\appdata\local\{CB79C22F-EA07-4897-A7C8-26D8CF79D461} 2011-08-06 07:25:31 ——– d—–w- c:\users\administrator\appdata\local\{3814F61F-9F37-41F0-8F62-25B8F3DBB2F8} 2011-08-05 16:57:56 ——– d—–w- c:\users\administrator\appdata\local\{310772BC-A328-44BC-808C-E83BC252D84B} 2011-08-05 16:57:44 ——– d—–w- c:\users\administrator\appdata\local\{8D004E80-3C16-4C90-84BD-7C759C42FA13} 2011-08-05 10:19:27 ——– d—–w- c:\users\administrator\appdata\local\{21A05121-1C17-4415-88B9-E1A7AB5217E8} 2011-08-05 10:19:23 ——– d—–w- c:\users\administrator\appdata\local\{F99A76BB-AAD1-48D2-8324-2D75A941ADE0} 2011-08-05 08:38:24 ——– d—–w- c:\users\administrator\appdata\local\{DAFDEA46-2964-42B8-A582-3A7DF3FD00AA} 2011-08-05 08:37:55 ——– d—–w- c:\users\administrator\appdata\local\{0898778D-4D58-4656-998F-81F669ACAEAA} 2011-08-05 07:23:05 ——– d—–w- c:\users\administrator\appdata\local\{BBC8F1B3-CB51-4E2F-B36D-52876BD3C11A} 2011-08-05 07:22:02 ——– d—–w- c:\users\administrator\appdata\local\{BAFD9873-4212-4111-A721-658964F91D82} 2011-08-04 19:59:01 ——– d—–w- c:\users\administrator\appdata\local\{DDC77CFB-2257-41B2-ABB7-EDB68CA2EEE1} 2011-08-04 19:58:57 ——– d—–w- c:\users\administrator\appdata\local\{4DF59B06-2AFD-406D-AA3D-AC1A54C442EE} 2011-08-04 15:22:01 ——– d—–w- c:\users\administrator\appdata\local\{E0145318-E3BA-451F-BFBF-92129CC7610D} 2011-08-04 15:21:53 ——– d—–w- c:\users\administrator\appdata\local\{E272FB67-4A50-4C64-BBF2-9F9231933952} 2011-08-04 06:34:58 ——– d—–w- c:\users\administrator\appdata\local\{4164523A-71A7-45FE-B604-ADC7B11F1D97} 2011-08-04 06:34:17 ——– d—–w- c:\users\administrator\appdata\local\{BBD597DC-9ECB-42BD-9FD7-0BCB6C19C967} 2011-08-03 20:55:48 ——– d—–w- c:\users\administrator\appdata\local\{E208CDA0-A5F1-45F3-80CB-FF2465B18ED4} 2011-08-03 20:55:38 ——– d—–w- c:\users\administrator\appdata\local\{9E2DDBCC-D7EB-4122-B475-54701859B6DE} 2011-08-03 12:10:21 ——– d—–w- c:\users\administrator\appdata\local\{74112BA2-2B4F-4952-BC9A-0C850C648F23} 2011-08-03 12:10:18 ——– d—–w- c:\users\administrator\appdata\local\{0DBEE2C4-5BD7-430A-9F4F-7E9C588518B0} 2011-08-03 07:15:20 ——– d—–w- c:\users\administrator\appdata\local\{F81B03C1-7D25-4C61-B6B8-2EED84A68D01} 2011-08-03 07:15:11 ——– d—–w- c:\users\administrator\appdata\local\{DF565CF5-4B87-4CD0-B4D7-FD7BB3BA0EFB} 2011-08-02 21:13:15 ——– d—–w- c:\users\administrator\appdata\local\{0FBEF69E-B0DA-4329-9ED5-60D2553D492E} 2011-08-02 21:13:11 ——– d—–w- c:\users\administrator\appdata\local\{EA3A99E7-2890-45F7-86B6-A276DD7B23E7} 2011-08-02 09:21:54 ——– d—–w- c:\users\administrator\appdata\local\{B8C447FF-94D8-40E1-A4ED-95F09F08196B} 2011-08-02 09:21:50 ——– d—–w- c:\users\administrator\appdata\local\{510C7CE9-895B-4441-A30D-70395836DCDE} 2011-08-02 07:33:49 ——– d—–w- c:\users\administrator\appdata\local\{DFF5BC7D-7DB3-4C93-8BC2-3357655A383B} 2011-08-02 07:33:06 ——– d—–w- c:\users\administrator\appdata\local\{A82C4724-318F-4079-9296-187CF45AB506} 2011-08-01 12:11:51 ——– d—–w- c:\users\administrator\appdata\local\{2B99A4D4-8738-4399-9DD2-CD6947C8AC29} 2011-08-01 12:11:39 ——– d—–w- c:\users\administrator\appdata\local\{647A8669-8AEA-4781-9711-0E16A2D612FF} 2011-08-01 09:13:18 ——– d—–w- c:\users\administrator\appdata\local\{F041A92B-311D-45DD-B7E1-4614F29CB707} 2011-08-01 09:12:46 ——– d—–w- c:\users\administrator\appdata\local\{72F11E4F-EEAA-4CCD-AD78-7F85D47BB1FF} 2011-08-01 02:06:25 ——– d—–w- c:\users\administrator\appdata\local\{2A38FD2B-2005-494C-97E2-386136E64A76} 2011-08-01 02:06:21 ——– d—–w- c:\users\administrator\appdata\local\{970BB22B-D22B-40C5-8750-13C7C0CD0A18} 2011-07-31 19:32:23 ——– d—–w- c:\users\administrator\appdata\local\{04CAF188-60FA-48DD-B1E6-C94D935FFBA2} 2011-07-31 19:31:51 ——– d—–w- c:\users\administrator\appdata\local\{7F7710C0-53CF-4648-A950-2C75535AC52A} 2011-07-31 16:51:17 ——– d—–w- c:\users\administrator\appdata\local\{0F16A178-D7F3-4515-AA6D-35B9624683C6} 2011-07-31 16:51:14 ——– d—–w- c:\users\administrator\appdata\local\{8F587036-9218-4220-ABE4-83BB7E940092} 2011-07-31 12:14:58 ——– d—–w- c:\users\administrator\appdata\local\{13010380-992C-42E8-BBC7-A8DC20F9F884} 2011-07-31 12:14:53 ——– d—–w- c:\users\administrator\appdata\local\{29311FAF-2460-498F-8AB9-FF6F16A4085E} 2011-07-31 06:30:42 ——– d—–w- c:\users\administrator\appdata\local\{A09BDBF0-241B-4FAB-832C-56CDD1969E3E} 2011-07-31 06:30:16 ——– d—–w- c:\users\administrator\appdata\local\{86B203D3-BFFB-44FC-9BF2-38E41292681B} 2011-07-30 12:50:54 ——– d—–w- c:\users\administrator\appdata\local\{B928AB7F-D8D7-483D-8A7B-438579F2789A} 2011-07-30 12:50:38 ——– d—–w- c:\users\administrator\appdata\local\{0511225A-AF81-4644-8874-26E7642797C0} 2011-07-30 11:59:24 ——– d—–w- c:\users\administrator\appdata\local\{48F49B49-A80D-4565-A5E2-D95373F6727B} 2011-07-30 11:59:16 ——– d—–w- c:\users\administrator\appdata\local\{772F8713-8E21-40F5-B60E-0E890D2E7ACC} 2011-07-30 07:40:18 ——– d—–w- c:\users\administrator\appdata\local\{D124507E-25B6-4C61-97EF-E4D74EB3500A} 2011-07-30 07:40:13 ——– d—–w- c:\users\administrator\appdata\local\{9128B1B3-6456-431C-961B-D7920C2BCDDC} 2011-07-29 20:01:42 ——– d—–w- c:\users\administrator\appdata\local\{F8A698BF-610F-4284-B8E3-25D77BAFE022} 2011-07-29 20:01:38 ——– d—–w- c:\users\administrator\appdata\local\{1AFEB63B-42A2-4BEC-ACBD-FE1B7760DBF6} 2011-07-29 19:45:04 ——– d—–w- c:\users\administrator\appdata\local\{16AE4DA0-1DAC-4E51-87AB-898B927DDE12} 2011-07-29 19:45:00 ——– d—–w- c:\users\administrator\appdata\local\{4BF8AA40-1DC4-43F6-B6AE-BB754F2CB0A5} 2011-07-29 12:41:01 ——– d—–w- c:\users\administrator\appdata\local\{5D186CC2-7EEA-4F68-8D1E-6B91C03606E8} 2011-07-29 12:40:48 ——– d—–w- c:\users\administrator\appdata\local\{A992BF6F-8EA1-47BA-96B9-6FBDE0117ED7} 2011-07-29 10:31:56 ——– d—–w- c:\users\administrator\appdata\local\{B6108513-FEF8-4193-AA7E-8868D9252507} 2011-07-29 10:31:48 ——– d—–w- c:\users\administrator\appdata\local\{4F9B5D14-EF0F-4448-95CE-6A0C470E5CB4} 2011-07-29 08:01:00 ——– d—–w- c:\users\administrator\appdata\local\{5CCB46A9-5A1C-4561-9402-DFD6CBC7AA33} 2011-07-29 07:59:48 ——– d—–w- c:\users\administrator\appdata\local\{E220DFF0-2B1F-40C4-812D-466D02368F64} 2011-07-28 21:09:50 ——– d—–w- c:\users\administrator\appdata\local\{D9CF0777-D45E-4725-83E0-1B25780F7905} 2011-07-28 21:09:46 ——– d—–w- c:\users\administrator\appdata\local\{996583AB-2147-40E0-80A4-3CF9B2D9C808} 2011-07-28 09:22:34 ——– d—–w- c:\users\administrator\appdata\local\{BDD4FB72-F9A7-4FD7-A6C5-C93154A74076} 2011-07-27 21:22:02 ——– d—–w- c:\users\administrator\appdata\local\{B0922736-8342-4B2F-AA70-C628F9B742F3} 2011-07-27 17:53:38 2982672 —-a-w- c:\program files\microsoft games\age of empires online\AOEOnline.exe 2011-07-27 17:53:38 152848 —-a-w- c:\program files\microsoft games\age of empires online\AOEOnlineReplace.exe 2011-07-27 17:53:38 10964240 —-a-w- c:\program files\microsoft games\age of empires online\Spartan.exe 2011-07-27 09:03:49 ——– d—–w- c:\users\administrator\appdata\local\{4660EFE3-D05E-4426-9D31-9804DFA57383} 2011-07-26 21:03:11 ——– d—–w- c:\users\administrator\appdata\local\{96C3B079-A6DE-4061-9CC2-08F21E7BC37B} 2011-07-26 09:02:31 ——– d—–w- c:\users\administrator\appdata\local\{B4E065CF-949F-4940-8CDD-362FAF16E2C5} 2011-07-25 13:39:03 2043392 —-a-w- c:\windows\system32\win32k.sys 2011-07-25 13:33:52 49152 —-a-w- c:\windows\system32\csrsrv.dll 2011-07-25 13:13:32 ——– d—–w- c:\users\administrator\appdata\local\{5B494605-B770-4544-9113-1D56659AE6A1} . ==================== Find3M ==================== . 2011-08-16 07:38:03 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-22 02:54:43 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-04 11:43:53 40112 —-a-w- c:\windows\avastSS.scr 2011-07-04 11:36:43 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-04 11:32:20 54104 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-05-29 08:11:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 08:11:20 22712 —-a-w- c:\windows\system32\drivers\mbam.sys . ============= FINISH: 12:31:19.68 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 22/04/2010 17:18:22 System Uptime: 23/08/2011 12:07:22 (0 hours ago) . Motherboard: MSI | | MS-7346 Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | CPU 1 | 2400/267mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 466 GiB total, 253.215 GiB free. D: is CDROM (UDF) E: is CDROM () G: is Removable H: is Removable I: is Removable J: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318} Description: Standard PS/2 Keyboard Device ID: ACPI\PNP0303\4&3816A047&0 Manufacturer: (Standard keyboards) Name: Standard PS/2 Keyboard PNP Device ID: ACPI\PNP0303\4&3816A047&0 Service: i8042prt . Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: Microsoft PS/2 Mouse Device ID: ACPI\PNP0F03\4&3816A047&0 Manufacturer: Microsoft Name: Microsoft PS/2 Mouse PNP Device ID: ACPI\PNP0F03\4&3816A047&0 Service: i8042prt . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Marvell Libertas 802.11b/g Wireless LAN Client Adapter Device ID: PCI\VEN_11AB&DEV_1FAA&SUBSYS_1FAA11AB&REV_43\4&5505873&0&3880 Manufacturer: Marvell Name: Marvell Libertas 802.11b/g Wireless LAN Client Adapter PNP Device ID: PCI\VEN_11AB&DEV_1FAA&SUBSYS_1FAA11AB&REV_43\4&5505873&0&3880 Service: MRV6X32P . ==== System Restore Points =================== . . ==== Installed Programs ====================== . Acrobat.com Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader X (10.1.0) Age of Empires Online Allora and The Broken Portal Apple Application Support Apple Mobile Device Support Apple Software Update avast! Free Antivirus Big Fish Games: Game Manager Bonjour calibre CCleaner Compatibility Pack for the 2007 Office system Creative ALchemy Creative Audio Control Panel Creative Diagnostics Creative Media Toolbox 6 Creative Media Toolbox 6 (Shared Components) Creative MediaSource 5 Creative Software AutoUpdate Creative Sound Blaster Properties D3DX10 Downtown Secrets Edraw Mind Map V4 ESET Online Scanner v3 Google Chrome Google Earth Plug-in Google Update Helper Guild Wars Harry Potter TM HiJackThis Host OpenAL Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) iCopyExpert 3.1.2 iTunes Java Auto Updater Java™ 6 Update 24 Junk Mail filter update Malwarebytes' Anti-Malware version 1.51.0.1200 Mesh Runtime Messenger Companion Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Age of Empires II Microsoft Age of Empires II: The Conquerors Expansion Microsoft Antimalware Microsoft Application Error Reporting Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Office File Validation Add-In Microsoft Office Outlook Connector Microsoft Office Standard Edition 2003 Microsoft Office Word Viewer 2003 Microsoft Publisher 98 Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox (3.6.14) Mozilla Thunderbird (3.1.7) MSVCRT NVIDIA Display Control Panel NVIDIA Drivers OGA Notifier 2.0.0048.0 PVSonyDll QuickTime Safari Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Segoe UI Sound Blaster X-Fi Spybot - Search & Destroy SpywareBlaster 4.4 Star Trek: Armada The Battle for Middle-earth ™ II Update for Microsoft .NET Framework 3.5 SP1 (KB963707) VC 9.0 Runtime Ventrilo Client Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Yahoo! Toolbar ZoneAlarm ZoneAlarm Toolbar . ==== Event Viewer Messages From Past Week ======== . 23/08/2011 12:09:04, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 23/08/2011 12:08:18, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt 23/08/2011 12:07:31, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23/08/2011 07:36:33, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 22/08/2011 19:56:51, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 22/08/2011 16:52:58, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 22/08/2011 16:50:15, Error: EventLog [6008] - The previous system shutdown at 16:49:06 on 22/08/2011 was unexpected. 22/08/2011 15:46:59, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Andrew-PC\Rebecca SID (S-1-5-21-3164612162-256102785-1375235700-1002) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 22/08/2011 14:32:21, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 22/08/2011 13:53:52, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 21/08/2011 14:01:25, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 21/08/2011 08:00:36, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 20/08/2011 21:29:12, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 20/08/2011 18:14:36, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 20/08/2011 17:13:20, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 20/08/2011 10:17:49, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 20/08/2011 09:17:32, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 19/08/2011 19:38:41, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 19/08/2011 16:50:24, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 19/08/2011 08:56:59, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 19/08/2011 08:11:19, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 18/08/2011 16:24:04, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 18/08/2011 15:15:54, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 18/08/2011 09:28:07, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 18/08/2011 07:41:26, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 17/08/2011 20:02:59, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 17/08/2011 16:24:20, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 17/08/2011 14:25:46, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 17/08/2011 10:36:50, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 17/08/2011 07:43:09, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 16/08/2011 15:18:44, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 16/08/2011 14:52:34, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: Real-time protection has stopped functioning for an unknown reason. Restart the service in order to recover. 16/08/2011 14:12:27, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 16/08/2011 10:38:34, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 16/08/2011 08:36:48, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. . ==== End Of File ===========================
I think I did what you wanted unchecking things but I have a monster log that cannot be posted as it is so large! Help? lol Do you want me to pasterr in a few parts??? Thanks
Ok ty here it comes lol


Part 1

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-23 15:42:12
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000058 SAMSUNG_ rev.CR10
Running: gmer.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\uwdiqpob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x90957202]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcConnectPort [0x90D13570]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcCreatePort [0x90D13E46]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0x90D12FC6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x909597F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x90959848]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x90D0C884]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x9095995E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x90D2DFA8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x90959746]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0x90D13AD0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0x90D27E42]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0x90D2826A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0x90D326FE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x9095979A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x9095990C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0x90D13C2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x90957226]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x90D0D5B4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x90D2FA50]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x90D2F346]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0x90D26C26]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x90956FF0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x90D3041A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0x90D30658]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKeyEx [0x90D30B0A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x9095724A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x90959D56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x90957CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x90959820]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x90959870]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x90D0D16C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x90959988]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x90959772]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenProcess [0x90D2A358]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x909598D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x909597C8]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenThread [0x90D29F46]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x90959936]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x90957BA0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0x90D314E0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x90D30DD4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0x90D12B5E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x90D31F40]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0x90D13292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x9095726E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x90957292]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x90D0D9BE]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0x90D31A68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x9095704A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x90957186]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x90D2EA6A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x90957162]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0x90D28F66]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0x90D28C96]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x909572B6]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateUserProcess [0x90D286DE]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 10D 82CB0890 4 Bytes [02, 72, 95, 90] {ADD DH, [EDX-0x6b]; NOP }
.text ntkrnlpa.exe!KeSetEvent + 13D 82CB08C0 8 Bytes [70, 35, D1, 90, 46, 3E, D1, …] {JO 0x37; RCL DWORD [EAX-0x6f2ec1ba], 0x1}
.text ntkrnlpa.exe!KeSetEvent + 1C1 82CB0944 4 Bytes [C6, 2F, D1, 90]
.text ntkrnlpa.exe!KeSetEvent + 1D1 82CB0954 16 Bytes [F0, 97, 95, 90, 48, 98, 95, …]
.text ntkrnlpa.exe!KeSetEvent + 1E9 82CB096C 4 Bytes [A8, DF, D2, 90]
.text …
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82DDB62F 5 Bytes JMP 9103DD4C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 82E34543 5 Bytes JMP 9103F7F2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82E3DE68 4 Bytes CALL 9095834B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82E41ADC 4 Bytes CALL 90958361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? C:\Users\ADMINI~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\csrss.exe[524] KERNEL32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 3 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigA + 4 76A46DDD 1 Byte [89]
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804
.text C:\Windows\system32\wininit.exe[592] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08
.text C:\Windows\system32\wininit.exe[592] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8
.text C:\Windows\system32\wininit.exe[592] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC
.text C:\Windows\system32\wininit.exe[592] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\services.exe[636] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[636] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[636] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[636] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[636] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[636] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[636] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\services.exe[636] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\lsass.exe[648] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600
.text C:\Windows\system32\lsass.exe[648] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804
.text C:\Windows\system32\lsass.exe[648] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\lsass.exe[648] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\lsass.exe[648] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[648] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\lsm.exe[656] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[808] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 004E0600
.text C:\Windows\system32\svchost.exe[808] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 004E0804
.text C:\Windows\system32\svchost.exe[808] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 004E0A08
.text C:\Windows\system32\svchost.exe[808] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 004E01F8
.text C:\Windows\system32\svchost.exe[808] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 004E03FC
.text C:\Windows\system32\svchost.exe[808] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\winlogon.exe[852] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[852] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 3 Bytes JMP 00050804
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfigA + 4 76A46DDD 1 Byte [89]
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00060600
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00060804
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001703FC
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00170600
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00171014
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00170804
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00170A08
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00170C0C
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00170E10
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001701F8
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[940] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000B0600
.text C:\Windows\system32\svchost.exe[940] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000B0804
.text C:\Windows\system32\svchost.exe[940] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000B0A08
.text C:\Windows\system32\svchost.exe[940] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000B01F8
.text C:\Windows\system32\svchost.exe[940] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000B03FC
.text C:\Windows\system32\svchost.exe[940] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00130600
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00130804
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00130A08
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001301F8
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001303FC
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00C90600
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00C90804
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00C90A08
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 00C901F8
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 00C903FC
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00150600
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00150804
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00150A08
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001501F8
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001503FC
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[1200] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\AUDIODG.EXE[1268] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1308] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000C0600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000C0804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000C0A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000C01F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000C03FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00480600
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00480804
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00480A08
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 004801F8
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 004803FC
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1388] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1388] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001703FC
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00170600
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00171014
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00170804
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00170A08
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00170C0C
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00170E10
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001701F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!IsWindowUnicode + 37 77D990B5 5 Bytes JMP 20C79270 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] kernel32.dll!OpenProcess
Part 2 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[1556] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[1556] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[1556] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00260600 .text C:\Windows\system32\svchost.exe[1556] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00260804 .text C:\Windows\system32\svchost.exe[1556] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00260A08 .text C:\Windows\system32\svchost.exe[1556] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[1556] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 002601F8 .text C:\Windows\system32\svchost.exe[1556] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 002603FC .text C:\Windows\system32\svchost.exe[1556] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\WUDFHost.exe[1668] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\WUDFHost.exe[1668] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\WUDFHost.exe[1668] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Windows\system32\WUDFHost.exe[1668] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\nvvsvc.exe[1728] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8 .text C:\Windows\system32\nvvsvc.exe[1728] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC .text C:\Windows\system32\nvvsvc.exe[1728] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001703FC .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00170600 .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00171014 .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00170804 .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00170A08 .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00170C0C .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00170E10 .text C:\Windows\system32\nvvsvc.exe[1728] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001701F8 .text C:\Windows\system32\nvvsvc.exe[1728] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600 .text C:\Windows\system32\nvvsvc.exe[1728] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804 .text C:\Windows\system32\nvvsvc.exe[1728] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08 .text C:\Windows\system32\nvvsvc.exe[1728] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8 .text C:\Windows\system32\nvvsvc.exe[1728] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001A03FC .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 001A0600 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 001A1014 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 001A0804 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 001A0A08 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 001A0C0C .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 001A0E10 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001A01F8 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 001B0600 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 001B0804 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 001B0A08 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001B01F8 .text C:\Windows\System32\ZoneLabs\vsmon.exe[1804] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001B03FC .text C:\Windows\system32\Dwm.exe[1908] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\Dwm.exe[1908] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\Dwm.exe[1908] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000D03FC .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 000D0600 .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 000D1014 .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 000D0804 .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 000D0A08 .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 000D0C0C .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 000D0E10 .text C:\Windows\system32\Dwm.exe[1908] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000D01F8 .text C:\Windows\system32\Dwm.exe[1908] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000F0600 .text C:\Windows\system32\Dwm.exe[1908] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000F0804 .text C:\Windows\system32\Dwm.exe[1908] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000F0A08 .text C:\Windows\system32\Dwm.exe[1908] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000F01F8 .text C:\Windows\system32\Dwm.exe[1908] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000F03FC .text C:\Windows\Explorer.EXE[1932] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\Explorer.EXE[1932] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\Explorer.EXE[1932] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\Explorer.EXE[1932] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\Explorer.EXE[1932] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Windows\Explorer.EXE[1932] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Windows\Explorer.EXE[1932] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Windows\Explorer.EXE[1932] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Windows\Explorer.EXE[1932] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Windows\System32\rundll32.exe[1944] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000601F8 .text C:\Windows\System32\rundll32.exe[1944] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000603FC .text C:\Windows\System32\rundll32.exe[1944] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Windows\System32\rundll32.exe[1944] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Windows\System32\rundll32.exe[1944] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001401F8 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001403FC .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 001D0600 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 001D0804 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 001D0A08 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001D01F8 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001D03FC .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001E03FC .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 001E0600 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 001E1014 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 001E0804 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 001E0A08 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 001E0C0C .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 001E0E10 .text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[2032] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001E01F8 .text C:\Windows\System32\spoolsv.exe[2192] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\spoolsv.exe[2192] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\System32\spoolsv.exe[2192] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\spoolsv.exe[2192] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00240600 .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00240804 .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00240A08 .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 002401F8 .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 002403FC .text C:\Windows\System32\spoolsv.exe[2192] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 5 Bytes JMP 209B37DD C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!IsWindowUnicode + 37 77D990B5 5 Bytes JMP 20C79270 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!EnableWindow 77D9CD8B 5 Bytes JMP 6AF198BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!DialogBoxParamW 77DC10B0 5 Bytes JMP 6AE715E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!DialogBoxIndirectParamW 77DC2EF5 5 Bytes JMP 6B065E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!DialogBoxParamA 77DD8152 5 Bytes JMP 6B065E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!DialogBoxIndirectParamA 77DD847D 5 Bytes JMP 6B065EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!MessageBoxIndirectA 77DED4D9 5 Bytes JMP 6B065DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!MessageBoxIndirectW 77DED5D3 5 Bytes JMP 6B065D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!MessageBoxExA 77DED639 5 Bytes JMP 6B065CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] USER32.dll!MessageBoxExW 77DED65D 5 Bytes JMP 6B065C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!closesocket 777F330C 5 Bytes JMP 20AE3BA8 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!recv 777F343A 5 Bytes JMP 20AE3C29 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!WSASend 777F4496 5 Bytes JMP 20AE3F07 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!send 777F659B 5 Bytes JMP 20AE3CD3 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!sendto 777F67C5 5 Bytes JMP 20AE3D71 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!WSARecv 777F8400 5 Bytes JMP 20AE3E15 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!WSASendDisconnect 7780A3E9 5 Bytes JMP 20AE409B C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[2208] WS2_32.dll!WSASendTo 7780A474 5 Bytes JMP 20AE3FCE C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000901F8 .text C:\Windows\system32\taskeng.exe[2212] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000903FC .text C:\Windows\system32\taskeng.exe[2212] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000C03FC .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 000C0600 .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 000C1014 .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 000C0804 .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 000C0A08 .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 000C0C0C .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 000C0E10 .text C:\Windows\system32\taskeng.exe[2212] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000C01F8 .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 008D0600 .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 008D0804 .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 008D0A08 .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 008D01F8 .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 008D03FC .text C:\Windows\system32\taskeng.exe[2212] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000901F8 .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000903FC .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000B03FC .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 000B0600 .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 000B1014 .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 000B0804 .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 000B0A08 .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 000B0C0C .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 000B0E10 .text C:\Windows\system32\svchost.exe[2224] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000B01F8 .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00120600 .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00120804 .text C:\Windows\system32\svchost.exe[2224] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00120A08 .text C:\Windows\system32\svchost.exe[2224] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2224] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001201F8 .text C:\Windows\system32\svchost.exe[2224] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001203FC .text C:\Windows\system32\svchost.exe[2224] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000901F8 .text C:\Windows\system32\taskeng.exe[2288] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000903FC .text C:\Windows\system32\taskeng.exe[2288] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000B03FC .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 000B0600 .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 000B1014 .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 000B0804 .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 000B0A08 .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 000B0C0C .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 000B0E10 .text C:\Windows\system32\taskeng.exe[2288] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000B01F8 .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000C0600 .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000C0804 .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000C0A08 .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000C01F8 .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000C03FC .text C:\Windows\system32\taskeng.exe[2288] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10 .text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2304] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\iTunes\iTunesHelper.exe[2320] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Program Files\iTunes\iTunesHelper.exe[2320] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Windows\ehome\ehtray.exe[2520] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\ehome\ehtray.exe[2520] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\ehome\ehtray.exe[2520] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\ehome\ehtray.exe[2520] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000C0600 .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000C0804 .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000C0A08 .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000C01F8 .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000C03FC .text C:\Windows\ehome\ehtray.exe[2520] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 001D0600 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 001D0804 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 001D0A08 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001D01F8 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001D03FC .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 009E03FC .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 009E0600 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 009E1014 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 009E0804 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 009E0A08 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 009E0C0C .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 009E0E10 .text C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[2588] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 009E01F8 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000601F8 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000603FC .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2624] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Program Files\Microsoft Security Client\msseces.exe[2648] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8 .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC .text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2684] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ntdll.dll!LdrLoadDll
Part 3 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Program Files\Bonjour\mDNSResponder.exe[2700] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2744] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00090600 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00090804 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00090A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000901F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000903FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2752] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[2760] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[2760] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[2760] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[2760] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00120600 .text C:\Windows\system32\svchost.exe[2760] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00120804 .text C:\Windows\system32\svchost.exe[2760] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00120A08 .text C:\Windows\system32\svchost.exe[2760] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2760] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001201F8 .text C:\Windows\system32\svchost.exe[2760] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001203FC .text C:\Windows\system32\svchost.exe[2760] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00090600 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00090804 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00090A08 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000901F8 .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000903FC .text C:\Program Files\Windows Sidebar\sidebar.exe[2832] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\svchost.exe[2864] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\svchost.exe[2864] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\svchost.exe[2864] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\svchost.exe[2864] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00310600 .text C:\Windows\system32\svchost.exe[2864] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00310804 .text C:\Windows\system32\svchost.exe[2864] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00310A08 .text C:\Windows\system32\svchost.exe[2864] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\svchost.exe[2864] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 003101F8 .text C:\Windows\system32\svchost.exe[2864] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 003103FC .text C:\Windows\system32\svchost.exe[2864] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000601F8 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000603FC .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001103FC .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00110600 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00111014 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00110804 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00110A08 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00110C0C .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00110E10 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001101F8 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00120600 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00120804 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00120A08 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001201F8 .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001203FC .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2984] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[2992] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[2992] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[2992] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\svchost.exe[2992] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[2992] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00090600 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00090804 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00090A08 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000901F8 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000903FC .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3104] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\SearchIndexer.exe[3168] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\SearchIndexer.exe[3168] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001703FC .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00170600 .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00171014 .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00170804 .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00170A08 .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00170C0C .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00170E10 .text C:\Windows\system32\SearchIndexer.exe[3168] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001701F8 .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600 .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804 .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08 .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8 .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC .text C:\Windows\system32\SearchIndexer.exe[3168] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3256] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10 .text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3376] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8 .text C:\Windows\system32\WUDFHost.exe[3416] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\WUDFHost.exe[3416] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\WUDFHost.exe[3416] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\WUDFHost.exe[3416] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Windows\system32\WUDFHost.exe[3416] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8 .text C:\Windows\ehome\ehmsas.exe[3580] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC .text C:\Windows\ehome\ehmsas.exe[3580] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600 .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014 .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804 .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08 .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10 .text C:\Windows\ehome\ehmsas.exe[3580] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8 .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Windows\ehome\ehmsas.exe[3580] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 5 Bytes JMP 209B37DD C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] kernel32.dll!CreateThread 7637CB2E 5 Bytes JMP 6AED71CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 6AF1204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!CallNextHookEx 77D98E3B 5 Bytes JMP 6AF37A4F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!IsWindowUnicode + 37 77D990B5 5 Bytes JMP 20C79270 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 6AF5EA08 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!EnableWindow 77D9CD8B 5 Bytes JMP 6AF198BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!DefWindowProcA 77D9DB88 7 Bytes JMP 6AED93F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!CreateWindowExA 77D9DC2A 2 Bytes JMP 6AEE3223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!CreateWindowExA + 3 77D9DC2D 2 Bytes [14, F3] {ADC AL, 0xf3} .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!CreateWindowExW 77DA1305 5 Bytes JMP 6AF3FE2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!DefWindowProcW 77DB03B4 7 Bytes JMP 6AF37AB2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!DialogBoxParamW 77DC10B0 5 Bytes JMP 6AE715E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!DialogBoxIndirectParamW 77DC2EF5 5 Bytes JMP 6B065E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!DialogBoxParamA 77DD8152 5 Bytes JMP 6B065E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!DialogBoxIndirectParamA 77DD847D 5 Bytes JMP 6B065EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!MessageBoxIndirectA 77DED4D9 5 Bytes JMP 6B065DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!MessageBoxIndirectW 77DED5D3 5 Bytes JMP 6B065D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!MessageBoxExA 77DED639 5 Bytes JMP 6B065CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] USER32.dll!MessageBoxExW 77DED65D 5 Bytes JMP 6B065C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] ole32.dll!OleLoadFromStream 77841E80 5 Bytes JMP 6B066676 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!closesocket 777F330C 5 Bytes JMP 20AE3BA8 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!recv 777F343A 5 Bytes JMP 20AE3C29 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!WSASend 777F4496 5 Bytes JMP 20AE3F07 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!send 777F659B 5 Bytes JMP 20AE3CD3 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!sendto 777F67C5 5 Bytes JMP 20AE3D71 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!WSARecv 777F8400 5 Bytes JMP 20AE3E15 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!WSASendDisconnect 7780A3E9 5 Bytes JMP 20AE409B C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[3596] WS2_32.dll!WSASendTo 7780A474 5 Bytes JMP 20AE3FCE C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe[3760] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Program Files\Windows Media Player\wmpnscfg.exe[3880] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 5 Bytes JMP 209B37DD C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] kernel32.dll!CreateThread 7637CB2E 5 Bytes JMP 6AED71CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 6AF1204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!CallNextHookEx 77D98E3B 5 Bytes JMP 6AF37A4F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!IsWindowUnicode + 37 77D990B5 5 Bytes JMP 20C79270 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 6AF5EA08 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!EnableWindow 77D9CD8B 5 Bytes JMP 6AF198BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!DefWindowProcA 77D9DB88 7 Bytes JMP 6AED93F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!CreateWindowExA 77D9DC2A 2 Bytes JMP 6AEE3223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!CreateWindowExA + 3 77D9DC2D 2 Bytes [14, F3] {ADC AL, 0xf3} .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!CreateWindowExW 77DA1305 5 Bytes JMP 6AF3FE2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!DefWindowProcW 77DB03B4 7 Bytes JMP 6AF37AB2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!DialogBoxParamW 77DC10B0 5 Bytes JMP 6AE715E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!DialogBoxIndirectParamW 77DC2EF5 5 Bytes JMP 6B065E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!DialogBoxParamA 77DD8152 5 Bytes JMP 6B065E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!DialogBoxIndirectParamA 77DD847D 5 Bytes JMP 6B065EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!MessageBoxIndirectA 77DED4D9 5 Bytes JMP 6B065DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!MessageBoxIndirectW 77DED5D3 5 Bytes JMP 6B065D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!MessageBoxExA 77DED639 5 Bytes JMP 6B065CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] USER32.dll!MessageBoxExW 77DED65D 5 Bytes JMP 6B065C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] ole32.dll!OleLoadFromStream 77841E80 5 Bytes JMP 6B066676 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!closesocket 777F330C 5 Bytes JMP 20AE3BA8 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!recv 777F343A 5 Bytes JMP 20AE3C29 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!WSASend 777F4496 5 Bytes JMP 20AE3F07 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!send 777F659B 5 Bytes JMP 20AE3CD3 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!sendto 777F67C5 5 Bytes JMP 20AE3D71 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!WSARecv 777F8400 5 Bytes JMP 20AE3E15 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!WSASendDisconnect 7780A3E9 5 Bytes JMP 20AE409B C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4176] WS2_32.dll!WSASendTo 7780A474 5 Bytes JMP 20AE3FCE C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
Part 4 the end! 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\System32\svchost.exe[4444] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\System32\svchost.exe[4444] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\System32\svchost.exe[4444] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\System32\svchost.exe[4444] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\System32\svchost.exe[4444] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\iPod\bin\iPodService.exe[4720] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\iPod\bin\iPodService.exe[4720] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Program Files\iPod\bin\iPodService.exe[4720] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600 .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804 .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08 .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8 .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC .text C:\Program Files\iPod\bin\iPodService.exe[4720] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 5 Bytes JMP 209B37DD C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] kernel32.dll!CreateThread 7637CB2E 5 Bytes JMP 6AED71CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 6AF1204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!CallNextHookEx 77D98E3B 5 Bytes JMP 6AF37A4F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!IsWindowUnicode + 37 77D990B5 5 Bytes JMP 20C79270 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 6AF5EA08 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!EnableWindow 77D9CD8B 5 Bytes JMP 6AF198BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!DefWindowProcA 77D9DB88 7 Bytes JMP 6AED93F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!CreateWindowExA 77D9DC2A 2 Bytes JMP 6AEE3223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!CreateWindowExA + 3 77D9DC2D 2 Bytes [14, F3] {ADC AL, 0xf3} .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!CreateWindowExW 77DA1305 5 Bytes JMP 6AF3FE2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!DefWindowProcW 77DB03B4 7 Bytes JMP 6AF37AB2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!DialogBoxParamW 77DC10B0 5 Bytes JMP 6AE715E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!DialogBoxIndirectParamW 77DC2EF5 5 Bytes JMP 6B065E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!DialogBoxParamA 77DD8152 5 Bytes JMP 6B065E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!DialogBoxIndirectParamA 77DD847D 5 Bytes JMP 6B065EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!MessageBoxIndirectA 77DED4D9 5 Bytes JMP 6B065DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!MessageBoxIndirectW 77DED5D3 5 Bytes JMP 6B065D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!MessageBoxExA 77DED639 5 Bytes JMP 6B065CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] USER32.dll!MessageBoxExW 77DED65D 5 Bytes JMP 6B065C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] ole32.dll!OleLoadFromStream 77841E80 5 Bytes JMP 6B066676 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!closesocket 777F330C 5 Bytes JMP 20AE3BA8 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!recv 777F343A 5 Bytes JMP 20AE3C29 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!WSASend 777F4496 5 Bytes JMP 20AE3F07 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!send 777F659B 5 Bytes JMP 20AE3CD3 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!sendto 777F67C5 5 Bytes JMP 20AE3D71 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!WSARecv 777F8400 5 Bytes JMP 20AE3E15 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!WSASendDisconnect 7780A3E9 5 Bytes JMP 20AE409B C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Internet Explorer\iexplore.exe[4788] WS2_32.dll!WSASendTo 7780A474 5 Bytes JMP 20AE3FCE C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10 .text C:\Program Files\Windows Live\Contacts\wlcomm.exe[4880] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 5 Bytes JMP 209B37DD C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10 .text C:\Program Files\CheckPoint\ZAForceField\ForceField.exe[4992] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00090600 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00090804 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00090A08 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000901F8 .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000903FC .text C:\Windows\system32\wbem\wmiprvse.exe[5604] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62] .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 003E0600 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 003E0804 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 003E0A08 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 003E01F8 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 003E03FC .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies) .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 003D03FC .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 003D0600 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 003D1014 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 003D0804 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 003D0A08 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 003D0C0C .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 003D0E10 .text C:\Users\Administrator\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe[5612] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 003D01F8 —- Devices - GMER 1.0.15 —- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software) AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) —- Registry - GMER 1.0.15 —- Reg HKLM\SYSTEM\CurrentControlSet\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet002\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet003\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet004\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet005\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet006\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet007\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet008\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet009\Services\nvlddmkm\Video@Service nvlddmkm Reg HKLM\SYSTEM\ControlSet024\Services\nvlddmkm\Video@Service nvlddmkm —- Files - GMER 1.0.15 —- File C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\3KDV9I1U.txt 254 bytes —- EOF - GMER 1.0.15 —- Good hunting ty
Hello ANDREW1959

Thank you for the logs.

Are there any other symptoms being displayed by your machine besides the unwanted e mails (error messages, popups, redirects etc)?

Please do let me know about this, its very important.

  • Security Programs


    • I can see from your log that you have a number of real-time security programs running, namely avast! Free Antivirus and Microsoft Security Essentials.
    • Whilst both of these programs provide good security, they may clash with each other which can leave your system vulnerable to infection.
    • You are advised to remove one of these programs.
    • Please make sure that you only have ONE Firewall and ONE real-time Antivirus running on your system.

  • Please disable Spybot Teatimer


    • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
    • On the left hand side, click "Tools", then click on the "Resident" icon in the list.
    • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active" box.
    • Click the "System Startup" icon in the List.
    • Uncheck the "TeaTimer" box and "OK" any prompts.
    • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
    • Exit Spybot S&D when done.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the MBAM log in your next reply along with the answer to my question.

    Have you changed your hotmail login password yet?
Hi Jon Tom sorry for the ommissions. Other Symptoms - On starting the computer it takes a little while but that is normal then I open IE and call up a page to browse but within maybe 30 secs it vanishes then afer another 1 /2 mins I can re-open and away to go. Also v occassionally IE crashes and has to be restarted. APart from that all else seems to be ok. Being a computer dummy I didnt realise about changing the hotmail password but have done so now, wil that stop it sending out more spam? After all is sorted out should I go for a different e-mail provider? Security - another basic question how do i switch off the Microsoft Security Essentials? S & D - Resident unchecked but no resident tea timer box to uncheck. - Sys. startup checked but again no tea timer box. Mbam clear here is the log Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7548 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 23/08/2011 21:47:41 mbam-log-2011-08-23 (21-47-41).txt Scan type: Quick scan Objects scanned: 219471 Time elapsed: 10 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thanks
Hello ANDREW1959

Thank you for the log.

I didnt realise about changing the hotmail password but have done so now, wil that stop it sending out more spam?

A compromised password may very well be responsible. You will have to ask your friends if they are still receiving spam from your account in order to determine if changing passwords has made any difference.

After all is sorted out should I go for a different e-mail provider?

Provided you have a good secure password I do not think changing e mail providers would be necessary.

another basic question how do i switch off the Microsoft Security Essentials?

If you decide you would like to remove Microsoft Security Essentials and keep avast! Free Antivirus as your resident security program, it must be uninstalled rather than switched off. To do this:


  • Please un-install Microsoft Security Essentials


    • Click on "Windows Orb" then on "Computer" and then on the "Uninstall or change a program" tab.
    • A list of currently installed programs will be displayed.
    • Find the "Microsoft Security Essentials" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Please update your Java


    • To update your Java, Click on the "Windows Orb" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

    There is not a great deal jumping out from the logs you have posted so far. May I ask if the "vanishing browser page" problem started at the same time as the spamming?

    Lets see what the following scan can tell us:

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the ESET log in your next reply along with a fresh DDS scan log :)
Hi hi, Even with changed password problem seems to continue :( The web page opening then vanishing has ben going on for a number of weeks the email busines started last weekend. Here's dds . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 10:01:16.35 on 24/08/2011 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1610 [GMT 1:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\ZoneLabs\vsmon.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\WUDFHost.exe C:\Windows\Explorer.EXE C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\System32\mobsync.exe C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe C:\Windows\System32\rundll32.exe C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Administrator\Pictures\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.co.uk/ uInternet Settings,ProxyOverride = *.local uURLSearchHooks: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll mURLSearchHooks: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll mURLSearchHooks: H - No File BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll TB: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Google Update] "c:\users\administrator\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe mRun: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab99160.cab DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-gb.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\admini~1\appdata\roaming\mozilla\firefox\profiles\bhwd8ppd.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo! FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\nos\bin\np_gp.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\administrator\appdata\local\google\update\1.3.21.57\npGoogleUpdate3.dll FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: ZoneAlarm Security Engine: {FFB96CC1-7EB3-449D-B827-DB661701C6BB} - c:\program files\checkpoint\zaforcefield\TrustChecker FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: avast! WebRep: [removed] - c:\program files\avast software\avast\webrep\FF FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-11 441176] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-11 309848] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-11 19544] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-4-11 54104] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-11 42184] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2009-10-14 26352] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2009-10-14 493032] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-4-11 1153368] R3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2009-5-6 413208] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-5-3 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-5-3 79360] S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\common files\creative labs shared\service\MT6Licensing.exe [2010-5-3 79360] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-26 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2011-5-13 1492840] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2008-1-21 21504] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] . =============== Created Last 30 ================ . 2011-08-24 06:59:38 7152464 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{1443838f-6950-4be4-9ac6-e85adb9fe546}\mpengine.dll 2011-08-24 06:39:01 ——– d—–w- c:\users\admini~1\appdata\local\{DEB59504-6432-43AD-89E0-84128C4DCD5B} 2011-08-24 06:38:57 ——– d—–w- c:\users\admini~1\appdata\local\{44072A98-907D-4351-ADC0-7489BAEBEE0C} 2011-08-23 18:38:36 ——– d—–w- c:\users\admini~1\appdata\local\{7CC6A110-122F-4DCB-994A-3930CB28E6AC} 2011-08-23 18:38:32 ——– d—–w- c:\users\admini~1\appdata\local\{157C6070-5CD4-49B1-834C-B8A1DF495379} 2011-08-23 06:38:11 ——– d—–w- c:\users\admini~1\appdata\local\{BB1C604F-80D9-4BEF-8D01-1FBE98F07DC1} 2011-08-23 06:37:31 ——– d—–w- c:\users\admini~1\appdata\local\{BB6634D5-56EE-4E34-AD4E-57819243E4A2} 2011-08-22 18:19:26 ——– d—–w- c:\users\admini~1\appdata\local\{DD577ECC-C74C-4DA0-A50F-B7E775D7A098} 2011-08-22 18:18:44 ——– d—–w- c:\users\admini~1\appdata\local\{BE38B40B-7201-4981-84FA-A142ED643B8D} 2011-08-22 16:04:38 ——– d—–w- c:\users\admini~1\appdata\roaming\My Battle for Middle-earth™ II Files 2011-08-22 15:38:25 51472 —-a-w- c:\program files\microsoft games\age of empires online\rmdll\final\RandomMap.dll 2011-08-22 15:38:25 19216 —-a-w- c:\program files\microsoft games\age of empires online\rmdll\final\CLRBinder.dll 2011-08-22 15:38:25 13584 —-a-w- c:\program files\microsoft games\age of empires online\rmdll\final\RandomMapBinder.dll 2011-08-22 15:27:27 81998 —-a-w- c:\program files\microsoft games\age of empires online\RockallDLL.dll 2011-08-22 15:27:27 746496 —-a-w- c:\program files\microsoft games\age of empires online\granny2.dll 2011-08-22 15:27:25 139536 —-a-w- c:\program files\microsoft games\age of empires online\eulax.dll 2011-08-22 15:27:24 173408 —-a-w- c:\program files\microsoft games\age of empires online\pw32b.dll 2011-08-22 15:17:24 452440 —-a-w- c:\windows\system32\d3dx10_40.dll 2011-08-22 15:17:24 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll 2011-08-22 15:17:24 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll 2011-08-22 15:16:47 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll 2011-08-22 15:16:46 81768 —-a-w- c:\windows\system32\xinput1_3.dll 2011-08-22 15:16:04 ——– d—–w- c:\windows\system32\xlive 2011-08-22 15:15:57 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE 2011-08-22 06:18:11 ——– d—–w- c:\users\admini~1\appdata\local\{7DEFB71C-E2A7-4D11-9123-F4527E95F954} 2011-08-22 06:17:10 ——– d—–w- c:\users\admini~1\appdata\local\{A4A3443F-5177-411C-A090-542205BB2EDC} 2011-08-20 20:19:26 ——– d—–w- c:\users\admini~1\appdata\local\{6E15B582-69C4-4947-A0BA-A887090C0BDB} 2011-08-20 20:19:22 ——– d—–w- c:\users\admini~1\appdata\local\{1A42ADFB-37CE-41B2-BB08-3178967AB59D} 2011-08-20 08:19:01 ——– d—–w- c:\users\admini~1\appdata\local\{EB9B4C8A-4926-4002-84CD-DE3CA9404A7F} 2011-08-20 08:18:22 ——– d—–w- c:\users\admini~1\appdata\local\{0E1D300C-B947-4A4A-98D9-67C884F9FDB6} 2011-08-19 07:13:23 ——– d—–w- c:\users\admini~1\appdata\local\{DBAF15B4-DC32-4547-B37E-44E1AC15478B} 2011-08-19 07:12:48 ——– d—–w- c:\users\admini~1\appdata\local\{84511C73-5352-4661-AB3C-ADBAD56F2326} 2011-08-18 18:43:40 ——– d—–w- c:\users\admini~1\appdata\local\{A0D4AE99-992C-49ED-867D-CA34DF2C280A} 2011-08-18 18:43:07 ——– d—–w- c:\users\admini~1\appdata\local\{F06E26C6-106D-429B-B548-CDA072FE2F8E} 2011-08-18 06:42:47 ——– d—–w- c:\users\admini~1\appdata\local\{9CED5CEF-31FA-4A9C-8D86-91C2EDDAE775} 2011-08-18 06:42:08 ——– d—–w- c:\users\admini~1\appdata\local\{8DE2A289-DC09-436B-8F8A-C1A65C6AF932} 2011-08-17 06:44:58 ——– d—–w- c:\users\admini~1\appdata\local\{59DC2B69-7799-40D5-8029-FC632E06F0DC} 2011-08-17 06:44:23 ——– d—–w- c:\users\admini~1\appdata\local\{A3F5645A-BE09-4EFD-81AC-A60EDA12BA79} 2011-08-16 07:37:38 ——– d—–w- c:\users\admini~1\appdata\local\{AAB23CB2-F8D0-4F11-92F7-0EF5183AD851} 2011-08-16 07:37:33 ——– d—–w- c:\users\admini~1\appdata\local\{A0F48B9A-9AD5-4490-9DF3-5EA7B54853F2} 2011-08-15 22:32:57 ——– d—–w- c:\users\admini~1\appdata\local\{4E355750-C353-4B59-9114-9C44AF6148C3} 2011-08-15 22:32:08 ——– d—–w- c:\users\admini~1\appdata\local\{483749DD-C772-4806-A489-EAE57405F568} 2011-08-15 08:37:58 ——– d—–w- c:\users\admini~1\appdata\local\{57B0045C-418F-4066-8952-8F5D63DC5B51} 2011-08-15 08:37:53 ——– d—–w- c:\users\admini~1\appdata\local\{7B66514C-8BDD-406B-82C4-21F6ACF39DBB} 2011-08-14 20:37:32 ——– d—–w- c:\users\admini~1\appdata\local\{749BE988-E587-44B2-A28E-75FDAB3311E9} 2011-08-14 20:36:51 ——– d—–w- c:\users\admini~1\appdata\local\{8A2A1527-00EC-4D17-9D3A-44F4617AA280} 2011-08-14 07:32:28 ——– d—–w- c:\users\admini~1\appdata\local\{05D69155-DD53-4CD4-B436-42F196C82807} 2011-08-14 07:32:24 ——– d—–w- c:\users\admini~1\appdata\local\{88DC7082-0688-496D-AA5B-777BCC3EA95C} 2011-08-13 12:03:52 ——– d—–w- c:\users\admini~1\appdata\local\{56887BED-7B7B-4AA1-B294-91B76B1819AF} 2011-08-13 12:03:17 ——– d—–w- c:\users\admini~1\appdata\local\{C0317D4A-883E-458F-8D82-FD18CC961BE4} 2011-08-12 22:02:56 ——– d—–w- c:\users\admini~1\appdata\local\{A1375CD1-EF92-44C0-BA70-2059C3DBA914} 2011-08-12 22:02:52 ——– d—–w- c:\users\admini~1\appdata\local\{8BC83B3B-2670-454A-929D-4FDCFB3F586A} 2011-08-12 10:02:47 ——– d—–w- c:\users\admini~1\appdata\local\{D8BDD23A-CAA5-4CF9-8D6B-7AD1E563954F} 2011-08-12 10:02:20 ——– d—–w- c:\users\admini~1\appdata\local\{F0259A1C-815D-4AB0-8EEE-F0DEEA6658C5} 2011-08-11 22:01:59 ——– d—–w- c:\users\admini~1\appdata\local\{957782BA-ECE3-4D21-B17E-D9EDC89B919D} 2011-08-11 22:01:29 ——– d—–w- c:\users\admini~1\appdata\local\{32CE3A8D-2DFE-43E7-BD8C-29CF96E7747F} 2011-08-11 10:01:08 ——– d—–w- c:\users\admini~1\appdata\local\{0EB86DE2-B469-43ED-BC2E-B476BBB2CDCE} 2011-08-11 10:01:03 ——– d—–w- c:\users\admini~1\appdata\local\{FB693ED0-23F5-4DC7-A507-7AC56E93E3D2} 2011-08-10 21:25:41 ——– d—–w- c:\users\admini~1\appdata\local\{0590E4B2-19F2-4B58-873A-4935DF7D63F0} 2011-08-10 21:25:37 ——– d—–w- c:\users\admini~1\appdata\local\{A8DF8092-0A37-44BC-9CA8-4449AC7F86A8} 2011-08-10 09:40:36 375808 —-a-w- c:\windows\system32\winsrv.dll 2011-08-10 09:40:32 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-08-10 09:40:27 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-08-10 09:40:16 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-10 09:40:15 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-10 09:40:13 913296 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-08-10 09:40:13 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2011-08-10 09:25:11 ——– d—–w- c:\users\admini~1\appdata\local\{7140477B-98A2-4709-A986-ECB14C8118C1} 2011-08-10 09:24:38 ——– d—–w- c:\users\admini~1\appdata\local\{AD4955EC-93FF-4BEA-B2FF-83666209B8BC} 2011-08-09 12:36:54 ——– d—–w- c:\users\admini~1\appdata\local\{50C4B87E-7029-4166-81F0-9D976AD13DEF} 2011-08-09 12:36:49 ——– d—–w- c:\users\admini~1\appdata\local\{9175BBA0-56D8-4457-846E-DAE0B4F3F3AA} 2011-08-09 09:58:08 ——– d—–w- c:\windows\en 2011-08-09 09:52:06 15712 —-a-w- c:\program files\common files\windows live\.cache\ffb8746e1cc567902\MeshBetaRemover.exe 2011-08-09 09:47:53 ——– d—–w- c:\users\admini~1\appdata\local\{679300A6-05CD-4235-8EE9-BBD294623509} 2011-08-09 09:47:49 ——– d—–w- c:\users\admini~1\appdata\local\{FE511940-9798-4DDA-BA03-225AE65164E9} 2011-08-09 08:35:24 ——– d—–w- c:\users\admini~1\appdata\local\{FC528296-6101-4834-8491-A97A2DC8486A} 2011-08-09 08:35:20 ——– d—–w- c:\users\admini~1\appdata\local\{60656F51-2216-4EC5-B0CF-37C8072D5C1B} 2011-08-08 20:04:26 ——– d—–w- c:\users\admini~1\appdata\local\{C0474FA6-56C9-468D-ABFF-203403E25036} 2011-08-08 20:04:18 ——– d—–w- c:\users\admini~1\appdata\local\{C49FC844-48E5-4480-A351-B424486F7EEE} 2011-08-08 08:54:35 ——– d—–w- c:\users\admini~1\appdata\local\{4F070646-E214-491A-9ED3-E0D48F37757E} 2011-08-08 08:54:21 ——– d—–w- c:\users\admini~1\appdata\local\{CAAEC758-835D-4DD4-8E89-B0A5F455971A} 2011-08-07 12:05:05 ——– d—–w- c:\users\admini~1\appdata\local\{6719D84D-6785-4AD6-9592-0635D1773D5A} 2011-08-07 12:05:01 ——– d—–w- c:\users\admini~1\appdata\local\{B36E0131-0F2B-405C-A7E9-AC9E4D6176C0} 2011-08-07 10:00:56 ——– d—–w- c:\users\admini~1\appdata\local\{8B547D1F-DA5E-4387-BFEE-D6EA3D0B795D} 2011-08-07 10:00:48 ——– d—–w- c:\users\admini~1\appdata\local\{113302E7-D0F0-4C3C-BBD0-12D55359211E} 2011-08-07 08:21:40 ——– d—–w- c:\users\admini~1\appdata\local\{1F5A40A8-2B4A-4802-B3CC-1A856A99A522} 2011-08-07 08:21:13 ——– d—–w- c:\users\admini~1\appdata\local\{1CA762B6-97DA-46A5-B715-1A5331B127E1} 2011-08-07 01:37:19 ——– d—–w- c:\users\admini~1\appdata\local\{B050B989-58D3-425F-8271-08805AF03E7E} 2011-08-07 01:37:15 ——– d—–w- c:\users\admini~1\appdata\local\{48C4EF7B-766F-4574-AE94-6F7D842E5061} 2011-08-06 12:20:24 ——– d—–w- c:\users\admini~1\appdata\local\{6C482C72-9737-491A-9ECD-72EA4E6C5742} 2011-08-06 12:19:44 ——– d—–w- c:\users\admini~1\appdata\local\{B47590D5-D425-483D-9444-740A34D111F7} 2011-08-06 11:48:21 ——– d—–w- c:\users\admini~1\appdata\local\{4E958182-98BC-4A8F-9A9D-992AA1B9BBEE} 2011-08-06 11:48:17 ——– d—–w- c:\users\admini~1\appdata\local\{DB5DF2BF-4DE7-4B24-A7A8-BF70C581E504} 2011-08-06 07:25:53 ——– d—–w- c:\users\admini~1\appdata\local\{CB79C22F-EA07-4897-A7C8-26D8CF79D461} 2011-08-06 07:25:31 ——– d—–w- c:\users\admini~1\appdata\local\{3814F61F-9F37-41F0-8F62-25B8F3DBB2F8} 2011-08-05 16:57:56 ——– d—–w- c:\users\admini~1\appdata\local\{310772BC-A328-44BC-808C-E83BC252D84B} 2011-08-05 16:57:44 ——– d—–w- c:\users\admini~1\appdata\local\{8D004E80-3C16-4C90-84BD-7C759C42FA13} 2011-08-05 10:19:27 ——– d—–w- c:\users\admini~1\appdata\local\{21A05121-1C17-4415-88B9-E1A7AB5217E8} 2011-08-05 10:19:23 ——– d—–w- c:\users\admini~1\appdata\local\{F99A76BB-AAD1-48D2-8324-2D75A941ADE0} 2011-08-05 08:38:24 ——– d—–w- c:\users\admini~1\appdata\local\{DAFDEA46-2964-42B8-A582-3A7DF3FD00AA} 2011-08-05 08:37:55 ——– d—–w- c:\users\admini~1\appdata\local\{0898778D-4D58-4656-998F-81F669ACAEAA} 2011-08-05 07:23:05 ——– d—–w- c:\users\admini~1\appdata\local\{BBC8F1B3-CB51-4E2F-B36D-52876BD3C11A} 2011-08-05 07:22:02 ——– d—–w- c:\users\admini~1\appdata\local\{BAFD9873-4212-4111-A721-658964F91D82} 2011-08-04 19:59:01 ——– d—–w- c:\users\admini~1\appdata\local\{DDC77CFB-2257-41B2-ABB7-EDB68CA2EEE1} 2011-08-04 19:58:57 ——– d—–w- c:\users\admini~1\appdata\local\{4DF59B06-2AFD-406D-AA3D-AC1A54C442EE} 2011-08-04 15:22:01 ——– d—–w- c:\users\admini~1\appdata\local\{E0145318-E3BA-451F-BFBF-92129CC7610D} 2011-08-04 15:21:53 ——– d—–w- c:\users\admini~1\appdata\local\{E272FB67-4A50-4C64-BBF2-9F9231933952} 2011-08-04 06:34:58 ——– d—–w- c:\users\admini~1\appdata\local\{4164523A-71A7-45FE-B604-ADC7B11F1D97} 2011-08-04 06:34:17 ——– d—–w- c:\users\admini~1\appdata\local\{BBD597DC-9ECB-42BD-9FD7-0BCB6C19C967} 2011-08-03 20:55:48 ——– d—–w- c:\users\admini~1\appdata\local\{E208CDA0-A5F1-45F3-80CB-FF2465B18ED4} 2011-08-03 20:55:38 ——– d—–w- c:\users\admini~1\appdata\local\{9E2DDBCC-D7EB-4122-B475-54701859B6DE} 2011-08-03 12:10:21 ——– d—–w- c:\users\admini~1\appdata\local\{74112BA2-2B4F-4952-BC9A-0C850C648F23} 2011-08-03 12:10:18 ——– d—–w- c:\users\admini~1\appdata\local\{0DBEE2C4-5BD7-430A-9F4F-7E9C588518B0} 2011-08-03 07:15:20 ——– d—–w- c:\users\admini~1\appdata\local\{F81B03C1-7D25-4C61-B6B8-2EED84A68D01} 2011-08-03 07:15:11 ——– d—–w- c:\users\admini~1\appdata\local\{DF565CF5-4B87-4CD0-B4D7-FD7BB3BA0EFB} 2011-08-02 21:13:15 ——– d—–w- c:\users\admini~1\appdata\local\{0FBEF69E-B0DA-4329-9ED5-60D2553D492E} 2011-08-02 21:13:11 ——– d—–w- c:\users\admini~1\appdata\local\{EA3A99E7-2890-45F7-86B6-A276DD7B23E7} 2011-08-02 09:21:54 ——– d—–w- c:\users\admini~1\appdata\local\{B8C447FF-94D8-40E1-A4ED-95F09F08196B} 2011-08-02 09:21:50 ——– d—–w- c:\users\admini~1\appdata\local\{510C7CE9-895B-4441-A30D-70395836DCDE} 2011-08-02 07:33:49 ——– d—–w- c:\users\admini~1\appdata\local\{DFF5BC7D-7DB3-4C93-8BC2-3357655A383B} 2011-08-02 07:33:06 ——– d—–w- c:\users\admini~1\appdata\local\{A82C4724-318F-4079-9296-187CF45AB506} 2011-08-01 12:11:51 ——– d—–w- c:\users\admini~1\appdata\local\{2B99A4D4-8738-4399-9DD2-CD6947C8AC29} 2011-08-01 12:11:39 ——– d—–w- c:\users\admini~1\appdata\local\{647A8669-8AEA-4781-9711-0E16A2D612FF} 2011-08-01 09:13:18 ——– d—–w- c:\users\admini~1\appdata\local\{F041A92B-311D-45DD-B7E1-4614F29CB707} 2011-08-01 09:12:46 ——– d—–w- c:\users\admini~1\appdata\local\{72F11E4F-EEAA-4CCD-AD78-7F85D47BB1FF} 2011-08-01 02:06:25 ——– d—–w- c:\users\admini~1\appdata\local\{2A38FD2B-2005-494C-97E2-386136E64A76} 2011-08-01 02:06:21 ——– d—–w- c:\users\admini~1\appdata\local\{970BB22B-D22B-40C5-8750-13C7C0CD0A18} 2011-07-31 19:32:23 ——– d—–w- c:\users\admini~1\appdata\local\{04CAF188-60FA-48DD-B1E6-C94D935FFBA2} 2011-07-31 19:31:51 ——– d—–w- c:\users\admini~1\appdata\local\{7F7710C0-53CF-4648-A950-2C75535AC52A} 2011-07-31 16:51:17 ——– d—–w- c:\users\admini~1\appdata\local\{0F16A178-D7F3-4515-AA6D-35B9624683C6} 2011-07-31 16:51:14 ——– d—–w- c:\users\admini~1\appdata\local\{8F587036-9218-4220-ABE4-83BB7E940092} 2011-07-31 12:14:58 ——– d—–w- c:\users\admini~1\appdata\local\{13010380-992C-42E8-BBC7-A8DC20F9F884} 2011-07-31 12:14:53 ——– d—–w- c:\users\admini~1\appdata\local\{29311FAF-2460-498F-8AB9-FF6F16A4085E} 2011-07-31 06:30:42 ——– d—–w- c:\users\admini~1\appdata\local\{A09BDBF0-241B-4FAB-832C-56CDD1969E3E} 2011-07-31 06:30:16 ——– d—–w- c:\users\admini~1\appdata\local\{86B203D3-BFFB-44FC-9BF2-38E41292681B} 2011-07-30 12:50:54 ——– d—–w- c:\users\admini~1\appdata\local\{B928AB7F-D8D7-483D-8A7B-438579F2789A} 2011-07-30 12:50:38 ——– d—–w- c:\users\admini~1\appdata\local\{0511225A-AF81-4644-8874-26E7642797C0} 2011-07-30 11:59:24 ——– d—–w- c:\users\admini~1\appdata\local\{48F49B49-A80D-4565-A5E2-D95373F6727B} 2011-07-30 11:59:16 ——– d—–w- c:\users\admini~1\appdata\local\{772F8713-8E21-40F5-B60E-0E890D2E7ACC} 2011-07-30 07:40:18 ——– d—–w- c:\users\admini~1\appdata\local\{D124507E-25B6-4C61-97EF-E4D74EB3500A} 2011-07-30 07:40:13 ——– d—–w- c:\users\admini~1\appdata\local\{9128B1B3-6456-431C-961B-D7920C2BCDDC} 2011-07-29 20:01:42 ——– d—–w- c:\users\admini~1\appdata\local\{F8A698BF-610F-4284-B8E3-25D77BAFE022} 2011-07-29 20:01:38 ——– d—–w- c:\users\admini~1\appdata\local\{1AFEB63B-42A2-4BEC-ACBD-FE1B7760DBF6} 2011-07-29 19:45:04 ——– d—–w- c:\users\admini~1\appdata\local\{16AE4DA0-1DAC-4E51-87AB-898B927DDE12} 2011-07-29 19:45:00 ——– d—–w- c:\users\admini~1\appdata\local\{4BF8AA40-1DC4-43F6-B6AE-BB754F2CB0A5} 2011-07-29 12:41:01 ——– d—–w- c:\users\admini~1\appdata\local\{5D186CC2-7EEA-4F68-8D1E-6B91C03606E8} 2011-07-29 12:40:48 ——– d—–w- c:\users\admini~1\appdata\local\{A992BF6F-8EA1-47BA-96B9-6FBDE0117ED7} 2011-07-29 10:31:56 ——– d—–w- c:\users\admini~1\appdata\local\{B6108513-FEF8-4193-AA7E-8868D9252507} 2011-07-29 10:31:48 ——– d—–w- c:\users\admini~1\appdata\local\{4F9B5D14-EF0F-4448-95CE-6A0C470E5CB4} 2011-07-29 08:01:00 ——– d—–w- c:\users\admini~1\appdata\local\{5CCB46A9-5A1C-4561-9402-DFD6CBC7AA33} 2011-07-29 07:59:48 ——– d—–w- c:\users\admini~1\appdata\local\{E220DFF0-2B1F-40C4-812D-466D02368F64} 2011-07-28 21:09:50 ——– d—–w- c:\users\admini~1\appdata\local\{D9CF0777-D45E-4725-83E0-1B25780F7905} 2011-07-28 21:09:46 ——– d—–w- c:\users\admini~1\appdata\local\{996583AB-2147-40E0-80A4-3CF9B2D9C808} 2011-07-28 09:22:34 ——– d—–w- c:\users\admini~1\appdata\local\{BDD4FB72-F9A7-4FD7-A6C5-C93154A74076} 2011-07-27 21:22:02 ——– d—–w- c:\users\admini~1\appdata\local\{B0922736-8342-4B2F-AA70-C628F9B742F3} 2011-07-27 17:53:38 2982672 —-a-w- c:\program files\microsoft games\age of empires online\AOEOnline.exe 2011-07-27 17:53:38 152848 —-a-w- c:\program files\microsoft games\age of empires online\AOEOnlineReplace.exe 2011-07-27 17:53:38 10964240 —-a-w- c:\program files\microsoft games\age of empires online\Spartan.exe 2011-07-27 09:03:49 ——– d—–w- c:\users\admini~1\appdata\local\{4660EFE3-D05E-4426-9D31-9804DFA57383} 2011-07-26 21:03:11 ——– d—–w- c:\users\admini~1\appdata\local\{96C3B079-A6DE-4061-9CC2-08F21E7BC37B} 2011-07-26 09:02:31 ——– d—–w- c:\users\admini~1\appdata\local\{B4E065CF-949F-4940-8CDD-362FAF16E2C5} 2011-07-25 13:39:03 2043392 —-a-w- c:\windows\system32\win32k.sys 2011-07-25 13:33:52 49152 —-a-w- c:\windows\system32\csrsrv.dll 2011-07-25 13:13:32 ——– d—–w- c:\users\admini~1\appdata\local\{5B494605-B770-4544-9113-1D56659AE6A1} . ==================== Find3M ==================== . 2011-08-16 07:38:03 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-22 02:54:43 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-04 11:43:53 40112 —-a-w- c:\windows\avastSS.scr . ============= FINISH: 10:05:23.57 =============== Here's ESET report………………. C:\Users\Administrator\Documents\Documents\Downloads\unconfirmed 56347.download Win32/RegistryBooster application
Hello ANDREW1959

Even with changed password problem seems to continue

Thanks for letting me know. There is not a great deal showing up in your scans so we'll have to dig a little deeper:

  • Please download SystemLook by JPShortstuff


    • Please download SystemLook by JPShortstuff by clicking here or here and save the file (called SystemLook.exe) to your desktop.
    • Right click on SystemLook.exe and select "Run as Administrator" to run the program.
    • Copy the content of the following codebox into the main textfield:

    :dir
    c:\users\admini~1\appdata\local\{8F587036-9218-4220-ABE4-83BB7E940092}
    c:\users\admini~1\appdata\local\{0898778D-4D58-4656-998F-81F669ACAEAA}
    c:\users\admini~1\appdata\local\{0EB86DE2-B469-43ED-BC2E-B476BBB2CDCE}
    c:\users\admini~1\appdata\local\{44072A98-907D-4351-ADC0-7489BAEBEE0C}
    c:\users\admini~1\appdata\local\{0E1D300C-B947-4A4A-98D9-67C884F9FDB6}

    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    • Note: The log can also be found on your Desktop entitled SystemLook.txt

  • Combofix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Right click on ComboFix.exe and select "Run as Administrator" to run the program. Follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

    Please post the SystemLook log and the ComboFix log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI