Hi Eddie,
Here is the result from Gmer i will post the panda scan next.
Thanks Annette
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-06-28 08:45:34
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xA8EE7794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xA8EE7F1E]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwTerminateProcess [0xA8EE6D0A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xA8EE6384]
---- Kernel code sections - GMER 1.0.14 ----
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.14 ----
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[184] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[208] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[216] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\bgsvcgen.exe[252] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\bgsvcgen.exe[252] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\bgsvcgen.exe[252] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\bgsvcgen.exe[252] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\bgsvcgen.exe[252] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\bgsvcgen.exe[252] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\bgsvcgen.exe[252] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[304] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[400] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[424] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[468] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[480] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[648] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[648] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[648] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[648] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[648] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[648] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[648] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[696] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[696] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[696] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[696] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[696] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[696] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\HPZipm12.exe[724] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\HPZipm12.exe[724] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\HPZipm12.exe[724] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\HPZipm12.exe[724] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\HPZipm12.exe[724] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\HPZipm12.exe[724] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\HPZipm12.exe[724] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\HPZipm12.exe[724] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\oodag.exe[736] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\oodag.exe[736] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\oodag.exe[736] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\oodag.exe[736] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\oodag.exe[736] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\oodag.exe[736] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\oodag.exe[736] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[764] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[864] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[884] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1044] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1044] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1044] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1044] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1044] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1044] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[1144] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1144] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1144] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1144] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1144] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1144] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1144] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1388] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\Explorer.EXE[1388] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\hkcmd.exe[1512] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\hkcmd.exe[1512] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\hkcmd.exe[1512] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\hkcmd.exe[1512] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\hkcmd.exe[1512] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\hkcmd.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\hkcmd.exe[1512] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\igfxpers.exe[1520] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\igfxpers.exe[1520] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\igfxpers.exe[1520] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\igfxpers.exe[1520] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\igfxpers.exe[1520] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\igfxpers.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\igfxpers.exe[1520] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Dell\Media Experience\DMXLauncher.exe[1556] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[1596] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1628] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[1704] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[1740] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[1752] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\oodtray.exe[1776] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\oodtray.exe[1776] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\oodtray.exe[1776] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\oodtray.exe[1776] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\oodtray.exe[1776] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\oodtray.exe[1776] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\oodtray.exe[1776] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\DellSupport\DSAgnt.exe[1796] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[1824] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[1824] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[1824] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[1824] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[1824] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[1824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Digital Line Detect\DLG.exe[1904] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2020] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2240] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2444] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ 67, 98, C3, 83 ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2832] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\System32\alg.exe[2916] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[2916] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\alg.exe[2916] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[2916] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\alg.exe[2916] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[2916] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[2916] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3084] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ 8B, 96, C3, 83 ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3224] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\gmer.exe[3848] ntdll.dll!NtCreateSection 7C90D793 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\gmer.exe[3848] ntdll.dll!NtCreateSection + 4 7C90D797 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\gmer.exe[3848] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\gmer.exe[3848] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\gmer.exe[3848] ntdll.dll!NtWriteVirtualMemory 7C90EA32 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\gmer.exe[3848] ntdll.dll!NtWriteVirtualMemory + 4 7C90EA36 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\gmer.exe[3848] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\gmer.exe[3848] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01A773CC] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [01A77376] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [01A77376] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01A773CC] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [01A77376] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01A773CC] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01A773CC] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [01A77376] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [01A77376] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01A773CC] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01A773CC] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[2832] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [01A77376] C:\Program Files\Mozilla Firefox\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Prog