Disabled COMODO and ran GMER. Here's the result and once again, thank you so much!!!
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2009-02-02 18:31:22
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xF72B5906]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xF72B4E66]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xF72B54C2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateKey [0xF72B60D0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xF72B4BC0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0xF72B6DC0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0xF72B5AEC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0xF72B4796]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteKey [0xF72B5D3A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteValueKey [0xF72B5EEA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDuplicateObject [0xF72B44F8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0xF72B6A42]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xF72B50AC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0xF72B56FA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenProcess [0xF72B4228]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0xF72B533C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenThread [0xF72B43A0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRenameKey [0xF72B6496]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xF72B4CDE]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xF72B67FA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xF72B6BF0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetValueKey [0xF72B6296]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xF72B5046]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0xF72B5230]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateProcess [0xF72B4A8A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xF72B4958]
---- Kernel code sections - GMER 1.0.14 ----
PAGE ntoskrnl.exe!SeAuditingFileEventsWithContext + 3D 805683FA 7 Bytes JMP 837D3178
---- User code sections - GMER 1.0.14 ----
.text C:\WINDOWS\System32\svchost.exe[356] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\System32\svchost.exe[356] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[356] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\System32\DSentry.exe[484] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\DSentry.exe[484] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[512] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe[520] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Windows Defender\MSASCui.exe[528] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MSASCui.exe[528] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[536] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\ctfmon.exe[664] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[664] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\winlogon.exe[692] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[692] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\services.exe[736] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[736] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\lsass.exe[748] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[748] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\svchost.exe[908] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[908] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\FinePixViewerS\QuickDCF2.exe[960] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\svchost.exe[976] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[976] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[1052] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1072] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\System32\svchost.exe[1128] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1128] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\System32\svchost.exe[1288] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1288] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\System32\svchost.exe[1368] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1368] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\spoolsv.exe[1492] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1492] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] kernel32.dll!ExitProcess 7C81CAFA 5 Bytes JMP 05052422 C:\Program Files\Google\Google Desktop Search\GoogleServices.DLL (Google Desktop/Google)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] USER32.dll!MessageBoxA 7E4507EA 5 Bytes JMP 050523CC C:\Program Files\Google\Google Desktop Search\GoogleServices.DLL (Google Desktop/Google)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] USER32.dll!MessageBoxW 7E466534 5 Bytes JMP 050523F7 C:\Program Files\Google\Google Desktop Search\GoogleServices.DLL (Google Desktop/Google)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[1752] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\Explorer.EXE[1792] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1792] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 0E, 98 ]
.text C:\WINDOWS\system32\cisvc.exe[1892] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 100050E0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\cisvc.exe[1892] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10005260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 00395810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00395740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 003953D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 003916D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] USER32.dll!keybd_event 7E466783 5 Bytes JMP 00391550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 00391860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 00391230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 003913C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 47, 88 ]
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 003950E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1904] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 00395260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 00375810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00375740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 003753D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 003716D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] USER32.dll!keybd_event 7E466783 5 Bytes JMP 00371550 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 00371860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 00371230 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] GDI32.dll!CreateDCW 77F1BE38 2 Bytes JMP 003713C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] GDI32.dll!CreateDCW + 3 77F1BE3B 2 Bytes [ 45, 88 ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 003750E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1952] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 00375260 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1992] ntdll.dll!NtClose 7C90CFD0 5 Bytes JMP 10005810 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1992] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 10005740 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[1992] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 100053D0 C:\WINDOWS\system32\guard32.