round five complete…
hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 11:57:17 AM, on 1/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\twstuff\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
https://itreg.sel.sony.com/sonysrvysa.asp?M…ture=03/11/2005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [VZRemoteCommander] C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [TVTunerLib] C:\Program Files\Common Files\Sony Shared\TVTunerLib\TVTLInstTool.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Transfer by Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://www.surveymonkey.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) -
http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1165985048703
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1165985029468
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
gmer log:
GMER 1.0.12.12011 -
http://www.gmer.net
Rootkit scan 2007-01-13 11:22:31
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.12 —-
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
—- User code sections - GMER 1.0.12 —-
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\explorer.exe[764] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\explorer.exe[764] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[880] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[880] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, CC, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, F8, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, D2, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] USER32.DLL!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, CF, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] USER32.DLL!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, C9, 77 ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 0A, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 14, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 10, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0D, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 07, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 0A, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 14, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 10, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0D, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 07, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!