GMER Log
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-11-10 13:27:48
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 Hitachi_HTS542516K9SA00 rev.BBCOC3BP
Running: rnmk5gkv.exe; Driver: C:\Users\Ryan\AppData\Local\Temp\kxldrpog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8E226202]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8E8FCCB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8E22881C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8E228874]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8E22898A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8E228772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8E2288C4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8E2287C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8E228938]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8E226226]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8E8FCD62]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8E225FF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8E22624A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8E228D82]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8E226CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8E22884C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8E22889C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8E2289B4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8E22879E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8E228904]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8E2287F4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8E228962]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8E8FCDFA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8E226BA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8E22626E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8E226292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8E22604A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8E226186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8E226162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8E2261AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8E2262B6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8E912902]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82A86349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82ABFD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82AC6D80 4 Bytes [02, 62, 22, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82AC6DA8 4 Bytes [B2, CC, 8F, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82AC6E5C 8 Bytes [1C, 88, 22, 8E, 74, 88, 22, ...] {SBB AL, 0x88; AND CL, [ESI-0x71dd778c]}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82AC6E68 4 Bytes [8A, 89, 22, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82AC6E84 4 Bytes [72, 87, 22, 8E]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82C53BE8 5 Bytes JMP 8E90E2BE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 82C6C1B8 5 Bytes JMP 8E90FD74 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82C812FF 4 Bytes CALL 8E22734B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82C9B0D1 4 Bytes CALL 8E227361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82D24F10 7 Bytes JMP 8E912906 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text sptd.sys 888AF000 8 Bytes [34, E2, A1, 82, A0, 47, A1, ...]
.text sptd.sys 888AF009 23 Bytes [47, A1, 82, 48, 6B, A1, 82, ...]
.text sptd.sys 888AF024 4 Bytes [44, E5, 9D, 88]
.text sptd.sys 888AF02C 100 Bytes [39, D6, CA, 82, 48, 99, C2, ...]
.text sptd.sys 888AF091 87 Bytes [45, A8, 82, 15, F5, A7, 82, ...]
.text ...
.sptd2 C:\Windows\System32\Drivers\sptd.sys entry point in ".sptd2" section [0x889A6D38]
? C:\Windows\System32\Drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload 8E9A3DB9 5 Bytes JMP 85A5E410
.text ayfuhx4w.SYS 94D95000 12 Bytes [44, 68, A1, 82, EE, 66, A1, ...]
.text ayfuhx4w.SYS 94D9500D 189 Bytes [47, A1, 82, 48, 6B, A1, 82, ...]
.text ayfuhx4w.SYS 94D950CB 285 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ayfuhx4w.SYS 94D951E9 470 Bytes [F8, 5C, 3A, 5E, 7C, 5F, BE, ...]
.text ayfuhx4w.SYS 94D953C0 99 Bytes [57, 80, 56, 30, 54, E0, 55, ...]
.text ...
.text peauth.sys AF161C9D 28 Bytes [44, CE, 65, D4, E8, C5, 2F, ...]
.text peauth.sys AF161CC1 28 Bytes [44, CE, 65, D4, E8, C5, 2F, ...]
.text user32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes [E9, 0A, 5C, 6E, 8A] {JMP 0xffffffff8a6e5c0f}
.text user32.dll!UnhookWinEvent 75B4B750 5 Bytes [E9, A7, 4C, 6E, 8A] {JMP 0xffffffff8a6e4cac}
.text user32.dll!SetWindowsHookExW 75B4E30C 5 Bytes [E9, F3, 24, 6E, 8A] {JMP 0xffffffff8a6e24f8}
.text user32.dll!SetWinEventHook 75B524DC 5 Bytes [E9, 17, DD, 6D, 8A] {JMP 0xffffffff8a6ddd1c}
.text user32.dll!SetWindowsHookExA 75B76D0C 5 Bytes [E9, EF, 98, 6B, 8A] {JMP 0xffffffff8a6b98f4}
.text kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\csrss.exe[408] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[460] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[460] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[460] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[460] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 001C0A08
.text C:\Windows\system32\wininit.exe[460] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001C03FC
.text C:\Windows\system32\wininit.exe[460] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 001C0804
.text C:\Windows\system32\wininit.exe[460] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001C01F8
.text C:\Windows\system32\wininit.exe[460] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 001C0600
.text C:\Windows\system32\csrss.exe[468] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\services.exe[520] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\services.exe[520] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\services.exe[520] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[544] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[544] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[544] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[544] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 000C0A08
.text C:\Windows\system32\winlogon.exe[544] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 000C03FC
.text C:\Windows\system32\winlogon.exe[544] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 000C0804
.text C:\Windows\system32\winlogon.exe[544] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 000C01F8
.text C:\Windows\system32\winlogon.exe[544] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 000C0600
.text C:\Windows\system32\lsass.exe[564] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[564] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[564] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\lsm.exe[580] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000F03FC
.text C:\Windows\system32\lsm.exe[580] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000F01F8
.text C:\Windows\system32\lsm.exe[580] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000503FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000501F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00080A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 000803FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00080804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 000801F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[668] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00080600
.text C:\Windows\system32\svchost.exe[676] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[676] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[676] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[764] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[764] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[764] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[856] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[856] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[856] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[856] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00230A08
.text C:\Windows\System32\svchost.exe[856] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 002303FC
.text C:\Windows\System32\svchost.exe[856] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00230804
.text C:\Windows\System32\svchost.exe[856] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 002301F8
.text C:\Windows\System32\svchost.exe[856] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00230600
.text C:\Windows\System32\svchost.exe[892] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[892] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[892] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[892] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00350A08
.text C:\Windows\System32\svchost.exe[892] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 003503FC
.text C:\Windows\System32\svchost.exe[892] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00350804
.text C:\Windows\System32\svchost.exe[892] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 003501F8
.text C:\Windows\System32\svchost.exe[892] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00350600
.text C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00A20A08
.text C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 00A203FC
.text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00A20804
.text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 00A201F8
.text C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00A20600
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1088] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 003C0A08
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 003C03FC
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 003C0804
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 003C01F8
.text C:\Windows\system32\svchost.exe[1088] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 003C0600
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1248] kernel32.dll!SetUnhandledExceptionFilter 759FF4FB 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1248] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[1340] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[1340] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[1340] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[1340] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\Dwm.exe[1340] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\Dwm.exe[1340] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\Dwm.exe[1340] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\Dwm.exe[1340] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 000F0600
.text C:\Windows\Explorer.EXE[1364] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[1364] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[1364] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[1364] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00110A08
.text C:\Windows\Explorer.EXE[1364] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001103FC
.text C:\Windows\Explorer.EXE[1364] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00110804
.text C:\Windows\Explorer.EXE[1364] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001101F8
.text C:\Windows\Explorer.EXE[1364] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00110600
.text C:\Program Files\Apoint\Apoint.exe[1516] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001503FC
.text C:\Program Files\Apoint\Apoint.exe[1516] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001501F8
.text C:\Program Files\Apoint\Apoint.exe[1516] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\Apoint\Apoint.exe[1516] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00170A08
.text C:\Program Files\Apoint\Apoint.exe[1516] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001703FC
.text C:\Program Files\Apoint\Apoint.exe[1516] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00170804
.text C:\Program Files\Apoint\Apoint.exe[1516] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001701F8
.text C:\Program Files\Apoint\Apoint.exe[1516] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00170600
.text C:\Windows\System32\igfxtray.exe[1528] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001603FC
.text C:\Windows\System32\igfxtray.exe[1528] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001601F8
.text C:\Windows\System32\igfxtray.exe[1528] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\igfxtray.exe[1528] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00200A08
.text C:\Windows\System32\igfxtray.exe[1528] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 002003FC
.text C:\Windows\System32\igfxtray.exe[1528] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00200804
.text C:\Windows\System32\igfxtray.exe[1528] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 002001F8
.text C:\Windows\System32\igfxtray.exe[1528] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00200600
.text C:\Windows\System32\hkcmd.exe[1536] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001603FC
.text C:\Windows\System32\hkcmd.exe[1536] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001601F8
.text C:\Windows\System32\hkcmd.exe[1536] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\hkcmd.exe[1536] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00200A08
.text C:\Windows\System32\hkcmd.exe[1536] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 002003FC
.text C:\Windows\System32\hkcmd.exe[1536] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00200804
.text C:\Windows\System32\hkcmd.exe[1536] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 002001F8
.text C:\Windows\System32\hkcmd.exe[1536] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00200600
.text C:\Windows\System32\igfxpers.exe[1548] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001603FC
.text C:\Windows\System32\igfxpers.exe[1548] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001601F8
.text C:\Windows\System32\igfxpers.exe[1548] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\igfxpers.exe[1548] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00190A08
.text C:\Windows\System32\igfxpers.exe[1548] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001903FC
.text C:\Windows\System32\igfxpers.exe[1548] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00190804
.text C:\Windows\System32\igfxpers.exe[1548] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001901F8
.text C:\Windows\System32\igfxpers.exe[1548] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00190600
.text C:\Windows\system32\igfxsrvc.exe[1620] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\igfxsrvc.exe[1620] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\igfxsrvc.exe[1620] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\system32\igfxsrvc.exe[1620] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\igfxsrvc.exe[1620] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\igfxsrvc.exe[1620] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\igfxsrvc.exe[1620] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\igfxsrvc.exe[1620] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001003FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00100804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001001F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[1680] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00100600
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001003FC
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00100804
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001001F8
.text C:\Program Files\iTunes\iTunesHelper.exe[1720] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00100600
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000A03FC
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000A01F8
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00140A08
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001403FC
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00140804
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001401F8
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[1728] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00140600
.text C:\Windows\System32\svchost.exe[1752] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000A03FC
.text C:\Windows\System32\svchost.exe[1752] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000A01F8
.text C:\Windows\System32\svchost.exe[1752] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1752] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00390A08
.text C:\Windows\System32\svchost.exe[1752] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 003903FC
.text C:\Windows\System32\svchost.exe[1752] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00390804
.text C:\Windows\System32\svchost.exe[1752] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 003901F8
.text C:\Windows\System32\svchost.exe[1752] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00390600
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00110A08
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 001103FC
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00110804
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 001101F8
.text C:\Program Files\Windows Sidebar\sidebar.exe[1756] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 00110600
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001603FC
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001601F8
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 002F0A08
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 002F03FC
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 002F0804
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] USER32.dll!SetWinEventHook 75B524DC 5 Bytes JMP 002F01F8
.text C:\Users\Ryan\AppData\Roaming\Google\Google Talk\googletalk.exe[1768] USER32.dll!SetWindowsHookExA 75B76D0C 5 Bytes JMP 002F0600
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] ntdll.dll!LdrUnloadDll 773AC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] ntdll.dll!LdrLoadDll 773B22B8 5 Bytes JMP 001601F8
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] kernel32.dll!GetBinaryTypeW + 70 75A169F4 1 Byte [62]
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] USER32.dll!UnhookWindowsHookEx 75B4ADF9 5 Bytes JMP 00300A08
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] USER32.dll!UnhookWinEvent 75B4B750 5 Bytes JMP 003003FC
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] USER32.dll!SetWindowsHookExW 75B4E30C 5 Bytes JMP 00300804
.text C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe[1836] USER32.dll!SetWinEventHook