**** First log created *******
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2008-10-22 19:00:39
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.14 —-
SSDT 86A5E6A8 ZwAlertResumeThread
SSDT 86A5E768 ZwAlertThread
SSDT 86A5EF80 ZwAllocateVirtualMemory
SSDT 86AA9800 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xF3F88EB0]
SSDT 86A87E58 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xF40B3794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xF40B3F1E]
SSDT 8638F738 ZwCreateThread
SSDT 86A87930 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xF3F89130]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xF3F89690]
SSDT 86A5EDE0 ZwFreeVirtualMemory
SSDT 86A87F48 ZwImpersonateAnonymousToken
SSDT 86A5E5E8 ZwImpersonateThread
SSDT 86A5ED00 ZwMapViewOfSection
SSDT 86A87D78 ZwOpenEvent
SSDT 86A686F0 ZwOpenProcessToken
SSDT 86A87BB8 ZwOpenSection
SSDT 86A5EAD8 ZwOpenThreadToken
SSDT 86A64F18 ZwResumeThread
SSDT 86EFB350 ZwSetContextThread
SSDT 86A5EBA8 ZwSetInformationProcess
SSDT 86A5E980 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xF3F898E0]
SSDT 86A87C98 ZwSuspendProcess
SSDT 86A3C218 ZwSuspendThread
SSDT 86A63710 ZwTerminateProcess
SSDT 86A77C00 ZwTerminateThread
SSDT 86F25668 ZwUnmapViewOfSection
SSDT 86A5EEB0 ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.14 —-
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.14 —-
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[492] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 36, 88 ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[548] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 12, 84 ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[612] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 02, 84 ]
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[684] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ AB, A1, C3, 83 ]
.text C:\WINDOWS\Explorer.EXE[696] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[696] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\Explorer.EXE[696] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[696] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\Explorer.EXE[696] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[696] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\Explorer.EXE[696] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, BB, 84 ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\ehome\mcrdsvc.exe[820] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, EE, 83 ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe[904] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, BA, 84 ]
.text C:\WINDOWS\system32\csrss.exe[932] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[932] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[932] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[932] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[932] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[932] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[932] KERNEL32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 73, 86 ]
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[960] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 9D, 84 ]
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[1004] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 18, 84 ]
.text C:\WINDOWS\system32\lsass.exe[1016] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1016] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1016] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1016] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1016] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1016] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1016] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 7E, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 4F, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 28, 84 ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1396] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 3B, 84 ]
.text C:\WINDOWS\System32\svchost.exe[1428] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1428] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1428] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1428] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1428] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1428] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1428] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 64, 88 ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[1480] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, B6, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 39, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1624] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1624] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1624] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1624] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1624] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1624] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1624] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 45, 84 ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\eHome\ehRecvr.exe[1676] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, EF, 83 ]
.text C:\WINDOWS\system32\svchost.exe[1708] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1708] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1708] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1708] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1708] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1708] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1708] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 02, 84 ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\eHome\ehSched.exe[1756] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 1D, 84 ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1916] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 83, 85 ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[1976] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 4F, 84 ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1980] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, F6, 83 ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2012] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 28, 85 ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2124] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, A3, 84 ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2304] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, AE, 84 ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[2368] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 72, 88 ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[2476] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, AE, 84 ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2692] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 58, 84 ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2800] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 5E, 84 ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Real\RealPlayer\RealPlay.exe[2816] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 3D, 85 ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe[2824] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, AF, 84 ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe[2856] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 8A, 84 ]
.text C:\apps\ABoard\ABoard.exe[2900] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\apps\ABoard\ABoard.exe[2900] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\apps\ABoard\ABoard.exe[2900] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\apps\ABoard\ABoard.exe[2900] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\apps\ABoard\ABoard.exe[2900] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\apps\ABoard\ABoard.exe[2900] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\apps\ABoard\ABoard.exe[2900] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 15, 84 ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe[2924] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 64, 84 ]
.text C:\apps\ABoard\AOSD.exe[2928] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\apps\ABoard\AOSD.exe[2928] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\apps\ABoard\AOSD.exe[2928] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\apps\ABoard\AOSD.exe[2928] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\apps\ABoard\AOSD.exe[2928] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\apps\ABoard\AOSD.exe[2928] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\apps\ABoard\AOSD.exe[2928] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 6B, 84 ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[2944] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 17, 85 ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[2964] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, BB, 87 ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Lexmark X74-X75\lxbbbmon.exe[2976] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 4F, 84 ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3008] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 41, 84 ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE[3016] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 9D, 84 ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\ehome\ehtray.exe[3024] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, EE, 84 ]
.text C:\WINDOWS\system32\rundll32.exe[3032] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3032] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3032] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3032] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3032] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3032] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3032] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 77, 84 ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\QuickTime\QTTask.exe[3040] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 76, 84 ]
.text C:\APPS\SMP\SmpSys.exe[3392] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\APPS\SMP\SmpSys.exe[3392] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\APPS\SMP\SmpSys.exe[3392] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\APPS\SMP\SmpSys.exe[3392] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\APPS\SMP\SmpSys.exe[3392] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\APPS\SMP\SmpSys.exe[3392] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\APPS\SMP\SmpSys.exe[3392] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, C1, 84 ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3444] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 81, 84 ]
.text C:\WINDOWS\system32\svchost.exe[3472] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[3472] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3472] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[3472] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3472] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[3472] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3472] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 4D, 84 ]
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3476] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ BF, A1, C3, 83 ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 2E, 84 ]
.text C:\WINDOWS\system32\wuauclt.exe[3512] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe[3548] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 67, 85 ]
.text C:\WINDOWS\system32\svchost.exe[3572] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[3572] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3572] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[3572] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3572] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[3572] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 6D, 84 ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 53, 86 ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!LoadResource 7C809FB5 7 Bytes JMP 28001CC0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!FindResourceExW 7C80AC88 7 Bytes JMP 28001B00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!FindResourceW 7C80BBCE 7 Bytes JMP 28001A80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!SizeofResource 7C80BC69 7 Bytes JMP 28001D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!FindResourceA 7C80BE89 7 Bytes JMP 28001B90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!LockResource 7C80CC97 5 Bytes JMP 28001DF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!CreateEventA 7C8308AD 5 Bytes JMP 28001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!FindResourceExA 7C835F78 7 Bytes JMP 28001C20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 0056DBBD C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (Windows Live Messenger/Microsoft Corporation)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] kernel32.dll!OutputDebugStringW 7C85A42D 5 Bytes JMP 28001E50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ADVAPI32.dll!CryptDeriveKey 77DEA685 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ADVAPI32.dll!CryptDecrypt 77DEA7B1 2 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ADVAPI32.dll!CryptDecrypt + 3 77DEA7B4 4 Bytes [ 21, B0, CC, CC ]
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!PeekMessageW 7E41929B 5 Bytes JMP 280040D0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 28003860 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!SetWindowRgn 7E41FFB2 7 Bytes JMP 280059B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!LoadIconW 7E420894 5 Bytes JMP 280062E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!LoadImageW 7E422CFE 5 Bytes JMP 280060F0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!CreateDialogParamW 7E427D4F 5 Bytes JMP 28005AF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!SetWindowPlacement 7E42D84C 5 Bytes JMP 28005870 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 28005CE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] USER32.dll!TrackPopupMenuEx 7E46CD28 5 Bytes JMP 280049B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WS2_32.dll!send 71AB428A 5 Bytes JMP 2800A210 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 28009FF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WS2_32.dll!recv 71AB615A 5 Bytes JMP 28009E50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 2800A3F0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 2800A630 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] SHELL32.dll!Shell_NotifyIconW 7CA261F5 5 Bytes JMP 28003020 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ole32.dll!CoInitializeEx 774FEF6B 5 Bytes JMP 28002100 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] ole32.dll!CoRegisterClassObject 77518720 5 Bytes JMP 28002200 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WININET.dll!InternetCloseHandle 7805DA59 5 Bytes JMP 28008FA0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WININET.dll!HttpOpenRequestA 78064341 5 Bytes JMP 28008C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 28008DF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[3580] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 28008ED0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 2A, 86 ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3712] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 2F, 84 ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe[3824] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 86, 84 ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 1F, 84 ]
.text C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe[3872] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\dllhost.exe[3940] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\dllhost.exe[3940] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\dllhost.exe[3940] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\dllhost.exe[3940] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\dllhost.exe[3940] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\dllhost.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\dllhost.exe[3940] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, E6, 83 ]
.text C:\WINDOWS\system32\dllhost.exe[3940] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\System32\alg.exe[4224] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4224] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\alg.exe[4224] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4224] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\alg.exe[4224] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4224] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[4224] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, EE, 83 ]
.text C:\WINDOWS\System32\alg.exe[4224] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, BC, 83 ]
.text C:\WINDOWS\eHome\ehmsas.exe[4376] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, BB, 83 ]
.text C:\HijackTHIS\GMER\gmer\gmer.exe[4620] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\System32\svchost.exe[4964] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[4964] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[4964] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[4964] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[4964] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[4964] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[4964] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, F6, 83 ]
.text C:\WINDOWS\System32\svchost.exe[4964] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
—- User IAT/EAT - GMER 1.0.14 —-
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [10001CA0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [1002B410] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRect] [1002B480] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [10001CA0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [1002B4A0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [10001CA0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowLongA] [1002B4A0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [10001C80] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [10001CA0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [10001CA0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [10001CD0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [10001C60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3668] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Sony Ericsson Mobile Communications AB)
—- Devices - GMER 1.0.14 —-
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device B5C6DC8A
AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Registry - GMER 1.0.14 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd502fe5
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0009dd502fe5
—- EOF - GMER 1.0.14 —-