Ok ty here it comes lol
Part 1
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-08-23 15:42:12
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000058 SAMSUNG_ rev.CR10
Running: gmer.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\uwdiqpob.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x90957202]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcConnectPort [0x90D13570]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcCreatePort [0x90D13E46]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0x90D12FC6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x909597F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x90959848]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x90D0C884]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x9095995E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x90D2DFA8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x90959746]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0x90D13AD0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0x90D27E42]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0x90D2826A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0x90D326FE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x9095979A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x9095990C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0x90D13C2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x90957226]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x90D0D5B4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x90D2FA50]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x90D2F346]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0x90D26C26]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x90956FF0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x90D3041A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0x90D30658]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKeyEx [0x90D30B0A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x9095724A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x90959D56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x90957CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x90959820]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x90959870]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x90D0D16C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x90959988]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x90959772]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenProcess [0x90D2A358]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x909598D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x909597C8]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenThread [0x90D29F46]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x90959936]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x90957BA0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0x90D314E0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x90D30DD4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0x90D12B5E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x90D31F40]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0x90D13292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x9095726E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x90957292]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x90D0D9BE]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0x90D31A68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x9095704A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x90957186]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x90D2EA6A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x90957162]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0x90D28F66]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0x90D28C96]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x909572B6]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateUserProcess [0x90D286DE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 10D 82CB0890 4 Bytes [02, 72, 95, 90] {ADD DH, [EDX-0x6b]; NOP }
.text ntkrnlpa.exe!KeSetEvent + 13D 82CB08C0 8 Bytes [70, 35, D1, 90, 46, 3E, D1, …] {JO 0x37; RCL DWORD [EAX-0x6f2ec1ba], 0x1}
.text ntkrnlpa.exe!KeSetEvent + 1C1 82CB0944 4 Bytes [C6, 2F, D1, 90]
.text ntkrnlpa.exe!KeSetEvent + 1D1 82CB0954 16 Bytes [F0, 97, 95, 90, 48, 98, 95, …]
.text ntkrnlpa.exe!KeSetEvent + 1E9 82CB096C 4 Bytes [A8, DF, D2, 90]
.text …
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82DDB62F 5 Bytes JMP 9103DD4C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 82E34543 5 Bytes JMP 9103F7F2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82E3DE68 4 Bytes CALL 9095834B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82E41ADC 4 Bytes CALL 90958361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? C:\Users\ADMINI~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\system32\csrss.exe[524] KERNEL32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 3 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigA + 4 76A46DDD 1 Byte [89]
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804
.text C:\Windows\system32\wininit.exe[592] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08
.text C:\Windows\system32\wininit.exe[592] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\wininit.exe[592] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8
.text C:\Windows\system32\wininit.exe[592] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC
.text C:\Windows\system32\wininit.exe[592] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\services.exe[636] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[636] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[636] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[636] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[636] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[636] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[636] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\services.exe[636] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[636] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\services.exe[636] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\lsass.exe[648] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00080600
.text C:\Windows\system32\lsass.exe[648] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00080804
.text C:\Windows\system32\lsass.exe[648] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\lsass.exe[648] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsass.exe[648] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\lsass.exe[648] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[648] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\lsm.exe[656] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\lsm.exe[656] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\lsm.exe[656] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[808] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[808] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 004E0600
.text C:\Windows\system32\svchost.exe[808] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 004E0804
.text C:\Windows\system32\svchost.exe[808] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 004E0A08
.text C:\Windows\system32\svchost.exe[808] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[808] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 004E01F8
.text C:\Windows\system32\svchost.exe[808] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 004E03FC
.text C:\Windows\system32\svchost.exe[808] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\winlogon.exe[852] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[852] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00050600
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 3 Bytes JMP 00050804
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfigA + 4 76A46DDD 1 Byte [89]
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\winlogon.exe[852] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00060600
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00060804
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001703FC
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00170600
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00171014
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00170804
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00170A08
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00170C0C
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00170E10
.text C:\Windows\system32\nvvsvc.exe[912] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001701F8
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\nvvsvc.exe[912] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[940] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000B0600
.text C:\Windows\system32\svchost.exe[940] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000B0804
.text C:\Windows\system32\svchost.exe[940] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000B0A08
.text C:\Windows\system32\svchost.exe[940] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[940] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000B01F8
.text C:\Windows\system32\svchost.exe[940] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000B03FC
.text C:\Windows\system32\svchost.exe[940] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00070600
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00070804
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00070A08
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000701F8
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000703FC
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10
.text c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe[1004] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00130600
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00130804
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00130A08
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001301F8
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001303FC
.text C:\Windows\System32\svchost.exe[1080] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00C90600
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00C90804
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00C90A08
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 00C901F8
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 00C903FC
.text C:\Windows\System32\svchost.exe[1128] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00150600
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00150804
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00150A08
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001501F8
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001503FC
.text C:\Windows\system32\svchost.exe[1140] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000803FC
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00081014
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00080804
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00080A08
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00080C0C
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00080E10
.text C:\Windows\system32\svchost.exe[1200] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\svchost.exe[1200] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1200] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\AUDIODG.EXE[1268] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1296] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1308] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1308] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000401F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000403FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00060600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00061014
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00060804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00060A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00060C0C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00060E10
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 000C0600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 000C0804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 000C0A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 000C01F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 000C03FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1340] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1380] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00480600
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00480804
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00480A08
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 004801F8
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 004803FC
.text C:\Windows\system32\svchost.exe[1380] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1388] kernel32.dll!SetUnhandledExceptionFilter 7635A8C5 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1388] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00170600
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00170804
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00170A08
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!FindWindowA 77D99D76 5 Bytes JMP 20C7828F C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001701F8
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001703FC
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] USER32.dll!FindWindowW 77DAA441 5 Bytes JMP 20C7825A C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ImpersonateNamedPipeClient 769D3A48 5 Bytes JMP 20C78E5D C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!SetThreadToken 769E8E21 5 Bytes JMP 20C79036 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001803FC
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00180600
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00181014
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00180804
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00180A08
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00180C0C
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00180E10
.text C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe[1436] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001801F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 001501F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 001503FC
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] kernel32.dll!OpenProcess 76377487 5 Bytes JMP 20C7846C C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] kernel32.dll!GetBinaryTypeW + 70 76382467 1 Byte [62]
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!CreateServiceW 76A09EB4 5 Bytes JMP 001703FC
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!DeleteService 76A0A07E 5 Bytes JMP 00170600
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!SetServiceObjectSecurity 76A46CD9 5 Bytes JMP 00171014
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfigA 76A46DD9 5 Bytes JMP 00170804
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfigW 76A46F81 5 Bytes JMP 00170A08
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfig2A 76A47099 5 Bytes JMP 00170C0C
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!ChangeServiceConfig2W 76A471E1 5 Bytes JMP 00170E10
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] ADVAPI32.dll!CreateServiceA 76A472A1 5 Bytes JMP 001701F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!SetWindowsHookExA 77D96322 5 Bytes JMP 00180600
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!SetWindowsHookExW 77D987AD 5 Bytes JMP 00180804
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!IsWindowUnicode + 37 77D990B5 5 Bytes JMP 20C79270 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!UnhookWindowsHookEx 77D998DB 5 Bytes JMP 00180A08
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!SetWinEventHook 77D99F3A 5 Bytes JMP 001801F8
.text C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe[1508] USER32.dll!UnhookWinEvent 77D9C06F 5 Bytes JMP 001803FC
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!LdrLoadDll 77BF93A8 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!LdrUnloadDll 77C0B740 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtAccessCheckByType 77C33E94 5 Bytes JMP 20C78791 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtAlpcImpersonateClientOfPort 77C34064 5 Bytes JMP 20C78DD9 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtImpersonateClientOfPort 77C34834 5 Bytes JMP 20C78D58 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtSetInformationProcess 77C35174 5 Bytes JMP 20C789AB C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (ZoneAlarm ForceField/Check Point Software Technologies)
.text C:\Windows\system32\svchost.exe[1556] kernel32.dll!OpenProcess