Here are the OTMoveIt3 and GMER results
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
========== SERVICES/DRIVERS ==========
Service npkycryp stopped successfully.
Service npkycryp deleted successfully.
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_4ni8zSCYFqUtUAEquaLJ scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ntdll64.dll scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01182009_092739
Files moved on Reboot…
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_4ni8zSCYFqUtUAEquaLJ not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be moved on reboot.
LoadLibrary failed for C:\WINDOWS\temp\ntdll64.dll
C:\WINDOWS\temp\ntdll64.dll NOT unregistered.
C:\WINDOWS\temp\ntdll64.dll moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\XUL.mfl moved successfully.
—————-
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2009-01-18 10:52:24
Windows 5.1.2600 Service Pack 3
—- System - GMER 1.0.14 —-
SSDT 8A499008 ZwConnectPort
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB7FD4350]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB7FD4580]
—- Kernel code sections - GMER 1.0.14 —-
? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified. !
—- User code sections - GMER 1.0.14 —-
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[780] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text c:\WINDOWS\system32\ZuneBusEnum.exe[832] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text c:\Program Files\Zune\ZuneNss.exe[1456] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[1692] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1748] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[2676] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
—- Devices - GMER 1.0.14 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \FileSystem\Fastfat \Fat B405AD20
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
—- EOF - GMER 1.0.14 —-
*********Again thank you for all the help you're giving me