MER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-07-21 07:01:19
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9250421ASG rev.DE17
Running: iggmoos0.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kgloapow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82E783C9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EB1D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\drivers\oyksu.sys The system cannot find the path specified. !
? System32\Drivers\speh.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 92693DB9 5 Bytes JMP 857A34E0
.text asinze92.SYS 932E1000 12 Bytes [44, 88, E0, 82, EE, 86, E0, ...]
.text asinze92.SYS 932E100D 9 Bytes [67, E0, 82, 48, 8B, E0, 82, ...] {LOOPNZW 0xffffffffffffff85; DEC EAX; MOV ESP, EAX; ADD BYTE [EAX], 0x0}
.text asinze92.SYS 932E1017 20 Bytes [00, DE, 57, 5B, 8B, E6, 55, ...]
.text asinze92.SYS 932E102C 149 Bytes [00, 00, 00, 00, 40, 32, E7, ...]
.text asinze92.SYS 932E10C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[252] kernel32.dll!SetUnhandledExceptionFilter 776CF4FB 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] ntdll.dll!LdrLoadDll 77C6223E 5 Bytes JMP 6BE7FA35 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] kernel32.dll!MapViewOfFile 776C93DB 5 Bytes JMP 6C12079E C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] kernel32.dll!VirtualAlloc 776CC43A 5 Bytes JMP 6C1207C5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] GDI32.dll!CreateDIBSection 77DE8850 5 Bytes JMP 6C120728 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] CRYPT32.dll!CryptImportPublicKeyInfoEx + 98 75EB39CA 7 Bytes JMP 007CEBF0
.text C:\Program Files\Mozilla Firefox\firefox.exe[308] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 1BFC 75EBA6E4 7 Bytes JMP 007CEC60
? C:\Windows\system32\services.exe[512] C:\Windows\system32\smss.exe image checksum mismatch; time/date stamp mismatch; unknown module: mswsock.dllunknown module: MSWSOCK.dll
.text C:\Windows\System32\spoolsv.exe[1408] ntdll.dll!NtClose 77C454C8 5 Bytes JMP 02016E80 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] ntdll.dll!NtMapViewOfSection 77C45C28 5 Bytes JMP 02018E40 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] ntdll.dll!NtQueryDirectoryFile 77C45F98 5 Bytes JMP 02015640 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!CopyFileW 776B6AF7 5 Bytes JMP 02019CC0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FlushFileBuffers 776B84E7 5 Bytes JMP 02017520 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!SetFileTime 776BC3E2 5 Bytes JMP 02017DE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!_hread 776BFAB0 5 Bytes JMP 02018300 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!_llseek 776BFADE 5 Bytes JMP 02018440 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!SetFilePointerEx 776BFB6A 5 Bytes JMP 020176F0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileSize 776C0823 5 Bytes JMP 02017830 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!CreateFileMappingW 776C120C 5 Bytes JMP 02018A60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!DeleteFileW 776C16EF 5 Bytes JMP 020181C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileTime 776C16FC 5 Bytes JMP 02017CE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!SetEndOfFile 776C2BA5 5 Bytes JMP 020179D0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileAttributesExW 776C307E 5 Bytes JMP 02017BF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!DeleteFileA 776C4382 5 Bytes JMP 02018080 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!MoveFileExW 776C8DB0 5 Bytes JMP 0201A3C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileSizeEx 776C99B1 5 Bytes JMP 02017900 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FindNextFileW 776C9B4E 5 Bytes JMP 020188A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!ReadFile 776C9B66 5 Bytes JMP 02016FF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FindNextFileA 776CA611 5 Bytes JMP 02018830 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FindFirstFileA 776CBF53 5 Bytes JMP 020184D0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!DuplicateHandle 776CD888 5 Bytes JMP 0201A750 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!CreateFileW 776CE8A5 5 Bytes JMP 02019560 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!CreateFileA 776CEA61 5 Bytes JMP 02019040 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!SetFilePointer 776D060D 5 Bytes JMP 020175A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FindFirstFileW 776D404C 5 Bytes JMP 020185C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileAttributesW 776D4C14 5 Bytes JMP 02017B70 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FindClose 776D4C24 5 Bytes JMP 020187C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!OpenFileMappingW 776D50EA 5 Bytes JMP 02018D20 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!WriteFile 776D53EE 5 Bytes JMP 02017270 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileType 776D6AB4 5 Bytes JMP 02017EE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!FindFirstFileExW 776D6BD6 5 Bytes JMP 020186B0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetFileAttributesA 776D6C06 5 Bytes JMP 02017AF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!ReplaceFile 776E1708 5 Bytes JMP 0201A650 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!CopyFileA 776E6D5A 5 Bytes JMP 02019AA0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!MoveFileW 776E6ED6 5 Bytes JMP 0201A150 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!UnlockFile 776E7B2B 5 Bytes JMP 02017FF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!LockFile 776E7B43 5 Bytes JMP 02017F60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!GetShortPathNameA 776E9CEE 5 Bytes JMP 02018910 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!MoveFileA 7770BF49 5 Bytes JMP 02019EE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] kernel32.dll!_hwrite 7770D505 5 Bytes JMP 020183A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] USER32.dll!GetDCEx 760A2D57 5 Bytes JMP 02015BD0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] USER32.dll!GetWindowDC 760A4AB7 2 Bytes JMP 02015C50 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] USER32.dll!GetWindowDC + 3 760A4ABA 2 Bytes [F7, 8B]
.text C:\Windows\System32\spoolsv.exe[1408] USER32.dll!ReleaseDC 760A5421 5 Bytes JMP 020161B0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] USER32.dll!GetDC 760A544C 5 Bytes JMP 02015B60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] USER32.dll!PrintWindow 760F4D87 5 Bytes JMP 02016340 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!DeleteDC 77DE6EAA 5 Bytes JMP 02016240 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!BitBlt 77DE72C0 5 Bytes JMP 02015CC0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!GetPixel 77DEC3D5 5 Bytes JMP 02015E70 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!CreateDCA 77DECCA9 5 Bytes JMP 020157A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!CreateDCW 77DECF79 5 Bytes JMP 02015980 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!StretchBlt 77DEF467 5 Bytes JMP 02016070 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!GetMetaFileW 77DF1260 2 Bytes JMP 02016840 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!GetMetaFileW + 3 77DF1263 2 Bytes [22, 8A]
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!GetEnhMetaFileW 77DF1341 5 Bytes JMP 02016950 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!CopyMetaFileW 77DF456F 5 Bytes JMP 02016A60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!GetMetaFileA 77E13CD5 5 Bytes JMP 02016410 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!CopyMetaFileA 77E147C6 5 Bytes JMP 02016630 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!StartDocW 77E15BB0 5 Bytes JMP 0201D190 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!StartDocA 77E160E1 5 Bytes JMP 0201C1E0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!CopyEnhMetaFileW 77E1D651 5 Bytes JMP 02016C70 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] GDI32.dll!GetEnhMetaFileA 77E1D758 5 Bytes JMP 02016520 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Windows\System32\spoolsv.exe[1408] ole32.dll!DoDragDrop 77BAA827 5 Bytes JMP 02018F40 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] ntdll.dll!NtClose 77C454C8 5 Bytes JMP 01746E80 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] ntdll.dll!NtMapViewOfSection 77C45C28 5 Bytes JMP 01748E40 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] ntdll.dll!NtQueryDirectoryFile 77C45F98 5 Bytes JMP 01745640 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!CopyFileW 776B6AF7 5 Bytes JMP 01749CC0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FlushFileBuffers 776B84E7 5 Bytes JMP 01747520 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!SetFileTime 776BC3E2 5 Bytes JMP 01747DE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!_hread 776BFAB0 5 Bytes JMP 01748300 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!_llseek 776BFADE 5 Bytes JMP 01748440 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!SetFilePointerEx 776BFB6A 5 Bytes JMP 017476F0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileSize 776C0823 5 Bytes JMP 01747830 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!CreateFileMappingW 776C120C 5 Bytes JMP 01748A60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!DeleteFileW 776C16EF 5 Bytes JMP 017481C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileTime 776C16FC 5 Bytes JMP 01747CE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!SetEndOfFile 776C2BA5 5 Bytes JMP 017479D0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileAttributesExW 776C307E 5 Bytes JMP 01747BF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!DeleteFileA 776C4382 5 Bytes JMP 01748080 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!MoveFileExW 776C8DB0 5 Bytes JMP 0174A3C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileSizeEx 776C99B1 5 Bytes JMP 01747900 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FindNextFileW 776C9B4E 5 Bytes JMP 017488A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!ReadFile 776C9B66 5 Bytes JMP 01746FF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FindNextFileA 776CA611 5 Bytes JMP 01748830 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FindFirstFileA 776CBF53 5 Bytes JMP 017484D0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!DuplicateHandle 776CD888 5 Bytes JMP 0174A750 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!CreateFileW 776CE8A5 5 Bytes JMP 01749560 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!CreateFileA 776CEA61 5 Bytes JMP 01749040 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!SetFilePointer 776D060D 5 Bytes JMP 017475A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FindFirstFileW 776D404C 5 Bytes JMP 017485C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileAttributesW 776D4C14 5 Bytes JMP 01747B70 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FindClose 776D4C24 5 Bytes JMP 017487C0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!OpenFileMappingW 776D50EA 5 Bytes JMP 01748D20 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!WriteFile 776D53EE 5 Bytes JMP 01747270 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileType 776D6AB4 5 Bytes JMP 01747EE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!FindFirstFileExW 776D6BD6 5 Bytes JMP 017486B0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetFileAttributesA 776D6C06 5 Bytes JMP 01747AF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!ReplaceFile 776E1708 5 Bytes JMP 0174A650 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!CopyFileA 776E6D5A 5 Bytes JMP 01749AA0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!MoveFileW 776E6ED6 5 Bytes JMP 0174A150 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!UnlockFile 776E7B2B 5 Bytes JMP 01747FF0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!LockFile 776E7B43 5 Bytes JMP 01747F60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!GetShortPathNameA 776E9CEE 5 Bytes JMP 01748910 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!MoveFileA 7770BF49 5 Bytes JMP 01749EE0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] kernel32.dll!_hwrite 7770D505 5 Bytes JMP 017483A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] USER32.dll!GetDCEx 760A2D57 5 Bytes JMP 01745BD0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] USER32.dll!GetWindowDC 760A4AB7 2 Bytes JMP 01745C50 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] USER32.dll!GetWindowDC + 3 760A4ABA 2 Bytes [6A, 8B] {PUSH -0x75}
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] USER32.dll!ReleaseDC 760A5421 5 Bytes JMP 017461B0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] USER32.dll!GetDC 760A544C 5 Bytes JMP 01745B60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] USER32.dll!PrintWindow 760F4D87 5 Bytes JMP 01746340 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!DeleteDC 77DE6EAA 5 Bytes JMP 01746240 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!BitBlt 77DE72C0 5 Bytes JMP 01745CC0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!GetPixel 77DEC3D5 5 Bytes JMP 01745E70 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!CreateDCA 77DECCA9 5 Bytes JMP 017457A0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!CreateDCW 77DECF79 5 Bytes JMP 01745980 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!StretchBlt 77DEF467 5 Bytes JMP 01746070 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!GetMetaFileW 77DF1260 2 Bytes JMP 01746840 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!GetMetaFileW + 3 77DF1263 2 Bytes [95, 89]
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!GetEnhMetaFileW 77DF1341 5 Bytes JMP 01746950 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!CopyMetaFileW 77DF456F 5 Bytes JMP 01746A60 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!GetMetaFileA 77E13CD5 5 Bytes JMP 01746410 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!CopyMetaFileA 77E147C6 5 Bytes JMP 01746630 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!StartDocW 77E15BB0 5 Bytes JMP 0174D190 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!StartDocA 77E160E1 5 Bytes JMP 0174C1E0 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!CopyEnhMetaFileW 77E1D651 5 Bytes JMP 01746C70 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] GDI32.dll!GetEnhMetaFileA 77E1D758 5 Bytes JMP 01746520 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)
.text C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe[2632] ole32.dll!DoDragDrop 77BAA827 5 Bytes JMP 01748F40 C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.DLL (Oracle IRM Library/Oracle Corporation)