forget about the post above...i was having some trouble...
this is actually the second scan....for some reason the first one comes up with 4 million characters so its way to big to post. its mostly all msmsgs files or what ever these are?? so this is after i hit scan a second time. if you need to see the other one i should email it or something.
GMER 1.0.12.12086 -
http://www.gmer.net
Rootkit scan 2007-03-09 20:16:16
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT 860DD1C8 ZwConnectPort
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- Kernel code sections - GMER 1.0.12 ----
? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified.
---- User code sections - GMER 1.0.12 ----
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[132] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\explorer.exe[144] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[144] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\explorer.exe[144] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\explorer.exe[144] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\explorer.exe[144] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\explorer.exe[144] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\explorer.exe[144] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\explorer.exe[144] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[308] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[308] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[308] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[308] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[308] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\dlcqcoms.exe[332] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\dlcqcoms.exe[332] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\dlcqcoms.exe[332] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\dlcqcoms.exe[332] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\dlcqcoms.exe[332] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\dlcqcoms.exe[332] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\dlcqcoms.exe[332] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\dlcqcoms.exe[332] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Spyware Doctor\sdhelp.exe[348] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\sdhelp.exe[348] user32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Spyware Doctor\sdhelp.exe[348] user32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\sdhelp.exe[348] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F040F5A
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE[408] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE[424] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\csrss.exe[584] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[584] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[584] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\csrss.exe[584] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\csrss.exe[584] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\csrss.exe[584] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\csrss.exe[584] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\csrss.exe[584] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\winlogon.exe[612] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[612] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[612] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[612] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\winlogon.exe[612] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\winlogon.exe[612] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\winlogon.exe[612] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\winlogon.exe[612] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\services.exe[656] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[656] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[656] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[656] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\services.exe[656] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\services.exe[656] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\services.exe[656] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\services.exe[656] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe[828] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ati2evxx.exe[896] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ati2evxx.exe[896] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ati2evxx.exe[896] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ati2evxx.exe[896] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ati2evxx.exe[896] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ati2evxx.exe[896] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\ati2evxx.exe[896] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\ati2evxx.exe[896] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[916] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[916] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[916] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\svchost.exe[916] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\svchost.exe[916] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\tcpsvcs.exe[992] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\tcpsvcs.exe[992] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\tcpsvcs.exe[992] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\tcpsvcs.exe[992] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\tcpsvcs.exe[992] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\tcpsvcs.exe[992] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\tcpsvcs.exe[992] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\tcpsvcs.exe[992] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[1000] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1000] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1000] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\svchost.exe[1000] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\svchost.exe[1000] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[1116] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[1156] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1156] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1156] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\svchost.exe[1156] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1204] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1204] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1204] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ati2evxx.exe[1228] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ati2evxx.exe[1228] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ati2evxx.exe[1228] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ati2evxx.exe[1228] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ati2evxx.exe[1228] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ati2evxx.exe[1228] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\ati2evxx.exe[1228] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\ati2evxx.exe[1228] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\svchost.exe[1332] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1332] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1332] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1332] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1332] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1332] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\svchost.exe[1332] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\svchost.exe[1332] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE[1412] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE[1452] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[1544] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[1564] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE[1608] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe[1616] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Dell Photo AIO Printer 966\memcard.exe[1644] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[1700] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\QuickTime\qttask.exe[1724] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\QuickTime\qttask.exe[1724] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[1724] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\QuickTime\qttask.exe[1724] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\QuickTime\qttask.exe[1724] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\QuickTime\qttask.exe[1724] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\QuickTime\qttask.exe[1724] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\QuickTime\qttask.exe[1724] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\QuickTime\qttask.exe[1724] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\spoolsv.exe[1808] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1808] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[1808] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[1808] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\spoolsv.exe[1808] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\spoolsv.exe[1808] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\spoolsv.exe[1808] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[1904] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\snmp.exe[1932] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\snmp.exe[1932] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\snmp.exe[1932] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\snmp.exe[1932] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\snmp.exe[1932] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\snmp.exe[1932] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\WINDOWS\system32\snmp.exe[1932] user32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\snmp.exe[1932] user32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\snmp.exe[1932] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Spyware Doctor\swdoctor.exe[1988] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\swdoctor.exe[1988] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Spyware Doctor\swdoctor.exe[1988] USER32.dll!DispatchMessageA 77D496B8 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\swdoctor.exe[1988] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F120F5A
.text C:\Program Files\Spyware Doctor\swdoctor.exe[1988] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Spyware Doctor\swdoctor.exe[1988] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[2032] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[2032] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\WINDOWS\system32\svchost.exe[2032] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\svchost.exe[2032] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\svchost.exe[2032] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ctfmon.exe[2136] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[2136] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2136] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[2136] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2136] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[2136] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\WINDOWS\system32\ctfmon.exe[2136] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\WINDOWS\system32\ctfmon.exe[2136] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\WINDOWS\system32\ctfmon.exe[2136] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[2164] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2216] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2596] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2992] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iPod\bin\iPodService.exe[2992] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[2992] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2992] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2992] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2992] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\iPod\bin\iPodService.exe[2992] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2992] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2992] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] GDI32.dll!Escape 77F26926 6 Bytes JMP 5F100F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] USER32.dll!DialogBoxParamW 77D5662C 5 Bytes JMP 7E1FF205 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes JMP 5F180F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes JMP 5F140F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] USER32.dll!DialogBoxIndirectParamW 77D62043 5 Bytes JMP 7E38FEBF C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3564] USER32.dll!MessageBoxIndirectA