Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Как да премахна System smart security ? [РЕШЕН]

Featured Replies

  • Автор

Даааа! :D Вече има интернет!!! Много, много, много благодаря! :wors: Само че на десктопа ми се появиха няколко полупрозрачни икони. Мога ли да ги изтрия и трябва ли да направя още нещо преди да се добави "решен" към темата?

Даааа! :D

Вече има интернет!!! Много, много, много благодаря! :wors:

Само че на десктопа ми се появиха няколко полупрозрачни икони.

Мога ли да ги изтрия и трябва ли да направя още нещо преди да се добави "решен" към темата?

Радвам се. Какви са тези икони ? Можете ли да ми кажете имената им или поне да снимате десктопа ? :P

А иначе преди да приключим искам да направим още малко проверки, защото до момента не сме проверили за рууткити и с антивирусна.

СТЪПКА 1

Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.

СТЪПКА 2

Следвайте следната инструкция за работа с Rootkit UnHooker:

  • Изтеглете този файл на десктопа.
  • Разархивирайте архива и стартирайте RkU3.8.388.590.exe, отидете на Report и сложете всички отметки. Натиснете OK.
  • Изчакайте програмата да завърши работа. След това кликнете на File, после Save Report. Запазете (Save as) файла с име report.txt на десктопа.
  • Публикувайте съдържанието на файла report.txt в следващия си коментар.

СТЪПКА 3

1) Изтеглете: ESET Online Scanner

2) Стартирайте esetsmartinstaller_enu.exe

3) Сложете отметка на YES, I accept the Terms of Use и изберете Start

4) Скенерът ще започне да изтегля компонентите, които са му необходими.

5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:

  • Scan archives
Scan for potentially unwanted applicationsScan for potentially unsafe applicationsEnable Anti-Stealth technology

Забележка: Не слагайте отметка пред Remove found threats

И накрая изберете Start

6) Скенерът ще започне да изтегля последните дефиниции.

7) След, като сканирането завърши изберете Finish.

8) Отидете в:

C:\Program Files\ESET\ESET Online Scanner

Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си пост тук.

След това ще реша дали сме готови за [РЕШЕН] :)

  • Автор

Прегледах си папките и намерих още от тези полупрозрачни папки. post-286802-0-09759700-1308311635_thumb. - тук в сравнание с нормални икони post-286802-0-25742600-1308311681_thumb. post-286802-0-95664100-1308311699_thumb. post-286802-0-64823200-1308311717_thumb. Някои са шорткътове. Но почти във всяка папка се появява полупрозрачен desktop.ini По стъпка 1: Стартирах aswMB, бутончето scan ми беше не активно, дадох направо save log и ето резултата: aswMBR version 0.9.6.399 Copyright© 2011 AVAST Software Run date: 2011-06-17 14:21:12 ----------------------------- 14:21:12.595 OS Version: Windows 6.0.6002 Service Pack 2 14:21:12.595 Number of processors: 2 586 0x170A 14:21:12.597 ComputerName: ELI4KA-PC UserName: 14:21:12.927 Initialze error 0 14:21:28.607 The log file has been saved successfully to "C:\Users\Elitsa Danailova\Desktop\aswMBR.txt" Незнам това ли трябваше да се получи

По-принцип проблема със скритите файлове и папки се решава лесно...просто мога да ви кажа как да не ги виждате повече, но зависи дали са били скрити от гадината. Имате ли липсващи икони в Start Menu-то...и има ли скрити икони на програми по десктопа...(такива които са били инсталирани преди да почнем да почистваме). Относно ASWmbr, стартирайте файла с десен бутон върху него => Run As administrator и вижте дали бутона SCAN вече е активен.

  • Автор

Стъпка 2 : репортът стана ужасно дълъг, ще го пусна на 3 части

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows Vista

Version 6.0.6002 (Service Pack 2)

Number of processors #2

==============================================

>SSDT State

==============================================

ntkrnlpa.exe-->NtAddBootEntry, Type: Address change 0x830C0EC6-->92B3A202 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateEvent, Type: Address change 0x8301DD37-->92B3C81C [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateEventPair, Type: Address change 0x830C6584-->92B3C874 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateIoCompletion, Type: Address change 0x82FD7907-->92B3C98A [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateMutant, Type: Address change 0x8302B7BC-->92B3C772 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateSection, Type: Address change 0x8303CD95-->92B3C8C4 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateSemaphore, Type: Address change 0x82FE2CC3-->92B3C7C6 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtCreateTimer, Type: Address change 0x82FC5A9F-->92B3C938 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtDeleteBootEntry, Type: Address change 0x830C0EF7-->92B3A226 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtLoadDriver, Type: Address change 0x82F76DEE-->92B39FF0 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtModifyBootEntry, Type: Address change 0x830C10C7-->92B3A24A [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtNotifyChangeKey, Type: Address change 0x82FCA5D9-->92B3CD82 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtNotifyChangeMultipleKeys, Type: Address change 0x82FC9A51-->92B3ACDA [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenEvent, Type: Address change 0x83004D5F-->92B3C84C [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenEventPair, Type: Address change 0x830C66B3-->92B3C89C [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenIoCompletion, Type: Address change 0x830786CD-->92B3C9B4 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenMutant, Type: Address change 0x8301CAF1-->92B3C79E [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenSection, Type: Address change 0x8301C5FD-->92B3C904 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenSemaphore, Type: Address change 0x82FB0EBE-->92B3C7F4 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtOpenTimer, Type: Address change 0x830C630F-->92B3C962 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtQueryObject, Type: Address change 0x82FF1343-->92B3ABA0 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtSetBootEntryOrder, Type: Address change 0x830C17F8-->92B3A26E [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtSetBootOptions, Type: Address change 0x830C1CFA-->92B3A292 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtSetSystemInformation, Type: Address change 0x82FF1E83-->92B3A04A [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtSetSystemPowerState, Type: Address change 0x830E50A1-->92B3A186 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtShutdownSystem, Type: Address change 0x830BE3A1-->92B3A162 [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtSystemDebugControl, Type: Address change 0x83003E51-->92B3A1AA [C:\windows\System32\Drivers\aswSnx.SYS]

ntkrnlpa.exe-->NtTerminateProcess, Type: Address change 0x82FFC0D3-->92ED0620 [C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS]

ntkrnlpa.exe-->NtVdmControl, Type: Address change 0x830B2EE3-->92B3A2B6 [C:\windows\System32\Drivers\aswSnx.SYS]

==============================================

>Shadow

==============================================

==============================================

>Processes

==============================================

0xA2EAFD90 [376] C:\Windows\explorer.exe (Microsoft Corporation, Windows Explorer)

0x8B1D7B68 [532] C:\Windows\System32\smss.exe (Microsoft Corporation, Windows Session Manager)

0x88D4ED90 [664] C:\Windows\System32\csrss.exe (Microsoft Corporation, Client Server Runtime Process)

0x8B582BE8 [728] C:\Windows\System32\wininit.exe (Microsoft Corporation, Windows Start-Up Application)

0x8B3E32E0 [740] C:\Windows\System32\csrss.exe (Microsoft Corporation, Client Server Runtime Process)

0xAAA24CA8 [768] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x8B5AF990 [772] C:\Windows\System32\services.exe (Microsoft Corporation, Services and Controller app)

0x89FDDB00 [784] C:\Windows\System32\lsass.exe (Microsoft Corporation, Local Security Authority Process)

0x8B5AA8D8 [792] C:\Windows\System32\lsm.exe (Microsoft Corporation, Local Session Manager Service)

0x8B7E1AA8 [880] C:\Windows\System32\winlogon.exe (Microsoft Corporation, Windows Logon Application)

0x8B7C6D90 [988] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x8B92FD90 [1052] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x8B946D90 [1084] C:\Program Files\Fingerprint Sensor\AtService.exe (AuthenTec, Inc., AFSS Service)

0x8B95DD90 [1100] C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard, HPFSService Application)

0x8B9C56A0 [1132] C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (SafeBoot International, Drive Encryption for HP ProtectTools Service)

0x8B9A5BF8 [1160] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xAAB735F8 [1192] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc., Catalyst Control Center: Monitoring program)

0x8B9FF688 [1204] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xA96F8D90 [1236] C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated, Synaptics Pointing Device Helper)

0xAA4F1D90 [1260] C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation, Andrea filters APO access service (32-bit))

0x923E8748 [1292] C:\Windows\System32\Ati2evxx.exe (ATI Technologies Inc., ATI External Event Utility EXE Module)

0x8A9196D0 [1320] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x928C1BE8 [1348] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x923F4D90 [1360] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xAA4163A0 [1368] C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe

0xAAA23B20 [1448] C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc., PsiService PsiService)

0xAA43BD90 [1460] C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company, LightScribe Service)

0x928D7D90 [1520] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x928F8720 [1544] C:\Windows\System32\SLsvc.exe (Microsoft Corporation, Microsoft Software Licensing Service)

0x9291B640 [1596] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x92995418 [1716] C:\Windows\System32\dwm.exe (Microsoft Corporation, Desktop Window Manager)

0xA9745020 [1724] C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity, ActivIdentity Event Service)

0x8B540308 [1732] C:\Windows\System32\hpservice.exe (Hewlett-Packard Corporation, HpService)

0x92962768 [1800] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xA2E13B20 [1828] C:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe (Bioscrypt Inc., Global Virtual Card Host)

0x929915F8 [1952] C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software, avast! Service)

0x929AFD90 [1976] C:\Windows\System32\Ati2evxx.exe (ATI Technologies Inc., ATI External Event Utility EXE Module)

0xAA5FB868 [2024] C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc, Dispatcher)

0xA2F4ED90 [2128] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation, Windows Defender User Interface)

0xA2F4A908 [2160] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation, Event Monitor User Notification Tool)

0xA2F75460 [2172] C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity, ActivIdentity card event handler)

0xA2FC1300 [2184] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe (Hewlett-Packard Development Company, L.P., HP ProtectTools Security Manager)

0xA2F53D90 [2208] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated, Synaptics TouchPad Enhancements)

0xA2F78D90 [2228] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard, HP Wireless Assistant main program)

0x9F262AC0 [2444] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe (Hewlett-Packard, File Sanitizer for HP ProtectTools)

0x9F24CD90 [2452] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe ( Hewlett-Packard Development Company, L.P., Quick Launch Buttons)

0x9F2063B0 [2476] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co., Hewlett-Packard Product Assistant)

0xA2FB6718 [2780] C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity, ActivIdentity Event Service)

0xA9798020 [2800] C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc., Application Updater)

0x9F249AD8 [2816] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation, GrooveMonitor Utility)

0xA2FCDD90 [2844] C:\Windows\System32\taskeng.exe (Microsoft Corporation, Task Scheduler Engine)

0xA2FF3D90 [2888] C:\Windows\System32\spoolsv.exe (Microsoft Corporation, Spooler SubSystem App)

0xA2FFD6E0 [2912] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc., SMax4PNP)

0xA2FDE688 [2932] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation, InstallShield Update Service Scheduler)

0xA2FD2020 [2948] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P., Volume related element)

0xA2FEA3E0 [2960] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc., PowerISO Virtual Drive Manager)

0xA2FD4408 [2992] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software, avast! Antivirus)

0xA9788D90 [3020] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xA93E4D90 [3080] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc., Search Settings)

0xA978BD90 [3136] C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc., Bonjour Service)

0xA970CD90 [3140] C:\Windows\System32\taskeng.exe (Microsoft Corporation, Task Scheduler Engine)

0xA97C6438 [3176] C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation., Bluetooth Support Server)

0xA9738D90 [3212] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xA9655B30 [3292] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation, Windows Sidebar)

0xA2E85D90 [3316] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company, -)

0x87B55AD8 [3448] C:\Windows\System32\wuauclt.exe (Microsoft Corporation, Windows Update)

0xA96CFD90 [3460] C:\Windows\ehome\ehtray.exe (Microsoft Corporation, Media Center Tray Applet)

0x929C8378 [3548] C:\Users\Elitsa Danailova\Program Files\DNA\btdna.exe (BitTorrent, Inc., DNA)

0xA9728020 [3576] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd, DAEMON Tools Lite)

0xA9701720 [3692] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation, Windows Sidebar)

0xA9649B20 [3740] C:\Windows\ehome\ehmsas.exe (Microsoft Corporation, Media Center Media Status Aggregator Service)

0xA963E980 [3780] C:\Program Files\Olympus\ib\olycamdetect.exe (OLYMPUS IMAGING CORP., OLYMPUS ib Resident Program)

0xA2E59B20 [3844] C:\Program Files\BitTorrent\bittorrent.exe (BitTorrent, Inc., BitTorrent)

0xA96808B0 [3888] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com, SUPERAntiSpyware Application)

0xAAA21D90 [3972] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0xAA4E3700 [4012] C:\Program Files\ActivIdentity\ActivClient\accoca.exe (ActivIdentity, ActivIdentity Cache Server)

0x92971D90 [4052] C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation., Bluetooth Tray Application)

0xAAA4A7A8 [4120] C:\Program Files\UGS\UGSLicensing\lmgrd.exe (Macrovision Corporation, -)

0xAAAB1D28 [4136] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x8A984D90 [4168] C:\Program Files\UGS\UGSLicensing\lmgrd.exe (Macrovision Corporation, -)

0x88DA2020 [4180] C:\Windows\System32\svchost.exe (Microsoft Corporation, Host Process for Windows Services)

0x88D70518 [4212] C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation, Microsoft Windows Search Indexer)

0xAAA2CD90 [4328] C:\Windows\System32\CNAB4RPK.EXE (CANON INC., Canon Advanced Printing Technology RPC Server Process)

0x928FD8E0 [4396] C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation., Bluetooth Stack COM Server)

0x92925648 [4468] C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation, RAID Monitor)

0xA96A44D0 [4796] C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P., hpqwmiex Module)

0x86AA3B68 [4828] C:\Windows\System32\MustBeRandomlyNamed\AkWHwtkhE6oEJtv.exe (UG North, RKULE, SR2 Normandy)

0x8B1EF310 [5024] C:\Windows\System32\Macromed\Flash\FlashUtil10n_ActiveX.exe (Adobe Systems, Inc., Adobe® Flash® Player Installer/Uninstaller 10.2 r152)

0xA9602020 [5348] C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation, WMI Provider Host)

0x8650E788 [5424] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc., Catalyst Control Centre: Host application)

0xAA58C3C8 [5816] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P., Com for QLB application)

0x87B45AA8 [5844] C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation, Internet Explorer)

0xA2E83020 [5856] C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe (-, HpqToaster Module)

0xAA591020 [6060] C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation, Sink to receive asynchronous callbacks for WMI client application)

0x867D1D90 [6084] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard, HP Health Check Service)

0x869B2D90 [7580] C:\Program Files\UGS\UGSLicensing\ugslmd.exe

0x87A3A900 [8120] C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation, Internet Explorer)

0x85F46860 [4] System

0x928CCD90 [1496] C:\Windows\System32\audiodg.exe (Microsoft Corporation, Windows Audio Device Graph Isolation )

==============================================

>Drivers

==============================================

0x8FE06000 C:\windows\system32\DRIVERS\atikmdag.sys 4640768 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver)

0x90606000 C:\windows\system32\DRIVERS\NETw5v32.sys 4272128 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver)

0x82E0B000 C:\windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System)

0x82E0B000 PnpManager 3907584 bytes

0x82E0B000 RAW 3907584 bytes

0x82E0B000 WMIxWDM 3907584 bytes

0x9D2A0000 Win32k 2113536 bytes

0x9D2A0000 C:\windows\System32\win32k.sys 2113536 bytes (Microsoft Corporation, Multi-User Win32 Driver)

0x91C01000 C:\windows\system32\DRIVERS\snp2uvc.sys 1761280 bytes (-, UVC Camera Streaming Driver)

0x8BE0B000 C:\windows\system32\drivers\ql2300.sys 1277952 bytes (QLogic Corporation, QLogic Fibre Channel Stor Miniport Driver)

0x8C408000 C:\windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver)

0x8C07C000 C:\windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)

0x8068B000 PCI_PNP0003 1048576 bytes

0x8068B000 sptd 1048576 bytes

0x8068B000 C:\windows\System32\Drivers\spzk.sys 1048576 bytes

0x8C20B000 C:\windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)

0x804DC000 C:\windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)

0xAF2A4000 C:\windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)

0x8C310000 C:\windows\System32\Drivers\dump_iaStor.sys 892928 bytes

0x83A0D000 C:\windows\system32\drivers\iastor.sys 892928 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)

0x8BC06000 C:\windows\system32\drivers\megasr.sys 749568 bytes (LSI Corporation, Inc., LSI MegaRAID Software RAID Driver)

0xA0244000 C:\windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)

0xAF200000 C:\windows\system32\drivers\hardlock.sys 671744 bytes (Aladdin Knowledge Systems Ltd., Hardlock Device Driver for Windows NT)

0x83AE7000 C:\windows\system32\drivers\iastorv.sys 659456 bytes (Intel Corporation, Intel Matrix Storage Manager driver (base))

0x90273000 C:\windows\System32\drivers\dxgkrnl.sys 655360 bytes (Microsoft Corporation, DirectX Graphics Kernel)

0x8BB43000 C:\windows\system32\drivers\elxstor.sys 606208 bytes (Emulex, Storport Miniport Driver for LightPulse HBAs)

0x9031F000 C:\windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)

0x92A81000 C:\windows\system32\drivers\btwaudio.sys 528384 bytes (Broadcom Corporation., Bluetooth Audio Device)

0xAB97E000 C:\windows\System32\Drivers\bthport.sys 524288 bytes (Microsoft Corporation, Bluetooth Bus Driver)

0x80602000 C:\windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)

0x92A0E000 C:\windows\system32\drivers\btwavdt.sys 471040 bytes (Broadcom Corporation., Broadcom Bluetooth AVDT Service)

0x8C00B000 C:\windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0x92B27000 C:\windows\System32\Drivers\aswSnx.SYS 458752 bytes (AVAST Software, avast! Virtualization Driver)

0x80412000 C:\windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)

0xA037B000 C:\windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)

0x8BA0C000 C:\windows\system32\drivers\adp94xx.sys 434176 bytes (Adaptec, Inc., Adaptec Windows SAS/SATA Storport Driver)

0x91A8A000 C:\windows\system32\drivers\ADIHdAud.sys 405504 bytes (Analog Devices, Inc., High Definition Audio Function Driver)

0x8BF43000 C:\windows\system32\drivers\ql40xx.sys 348160 bytes (QLogic Corporation, QLogic iSCSI Storport Miniport Driver)

0xAB905000 C:\windows\System32\DRIVERS\srv.sys 323584 bytes (Microsoft Corporation, Server driver)

0x90A19000 C:\windows\system32\DRIVERS\yk60x86.sys 323584 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.)

0x9D4F0000 C:\windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)

0x8BA76000 C:\windows\system32\drivers\adpahci.sys 311296 bytes (Adaptec, Inc., Adaptec Windows SATA Storport Driver)

0x92F75000 C:\windows\System32\Drivers\aswSP.SYS 303104 bytes (AVAST Software, avast! self protection module)

0x83850000 C:\windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)

0x92E3A000 C:\windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0x807BA000 C:\windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)

0x8049B000 C:\windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)

0x83967000 C:\windows\system32\drivers\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)

0x903B7000 C:\windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0x92EF0000 C:\windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0x8BCED000 C:\windows\system32\drivers\uliahci.sys 245760 bytes (ULi Electronics Inc., ULi SATA Controller Driver)

0x8C1B2000 C:\windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)

0xAB88C000 C:\windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)

0x8C520000 C:\windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)

0xA0209000 C:\windows\system32\drivers\aswMonFlt.sys 229376 bytes (AVAST Software, avast! File System Minifilter for Windows 2003/Vista)

0x90AE1000 C:\windows\System32\Drivers\as1zrnqw.SYS 225280 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)

0x839C0000 C:\windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)

0x831C5000 ACPI_HAL 208896 bytes

0x831C5000 C:\windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0x8BD76000 C:\windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0x92E08000 C:\windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)

0x90A8B000 C:\windows\system32\DRIVERS\SynTP.sys 200704 bytes (Synaptics Incorporated, Synaptics Touchpad Driver)

0xA02F4000 C:\windows\system32\DRIVERS\RMCAST.sys 196608 bytes (Microsoft Corporation, Reliable Multicast Transport)

0x90B30000 C:\windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)

0x838B6000 C:\windows\system32\DRIVERS\pcmcia.sys 184320 bytes (Microsoft Corporation, PCMCIA Bus Driver)

0x91A38000 C:\windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0x8BD29000 C:\windows\system32\drivers\ulsata2.sys 180224 bytes (Promise Technology, Inc., Promise SATAII150 Series Windows Drivers)

0x8C187000 C:\windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)

0x8BDD1000 C:\windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)

0xA0334000 C:\windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)

0xAF3D5000 C:\windows\system32\DRIVERS\rfcomm.sys 167936 bytes (Microsoft Corporation, Bluetooth RFCOMM Driver)

0x92F2C000 C:\windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)

0xAB8DD000 C:\windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver)

0x8C59E000 C:\windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)

0x805C4000 C:\windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)

0x8BADD000 C:\windows\system32\drivers\adpu320.sys 155648 bytes (Adaptec, Inc., Adaptec StorPort Ultra320 SCSI Driver)

0x80794000 C:\windows\System32\Drivers\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver)

0x91A65000 C:\windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0x90B8C000 C:\windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0x92EC6000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS)

0x8393E000 C:\windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)

0xAB84C000 C:\windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0x8BFDC000 C:\windows\system32\drivers\ulsata.sys 135168 bytes (Promise Technology, Inc., Promise Ultra/Sata Series Driver for Win2003)

0x92BC3000 C:\windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)

0x8BD55000 C:\windows\system32\drivers\vsmraid.sys 135168 bytes (VIA Technologies Inc.,Ltd, VIA RAID DRIVER FOR AMD-X86-64)

0xAB86D000 C:\windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0x83B90000 C:\windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)

0xAB801000 C:\windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)

0x83809000 C:\windows\system32\drivers\mpio.sys 114688 bytes (Microsoft Corporation, MultiPath Support Bus-Driver)

0x8BAC2000 C:\windows\system32\drivers\adpu160m.sys 110592 bytes (Adaptec, Inc., Adaptec LH Ultra160 Driver (x86))

0x8C2F5000 C:\windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)

0x91BD7000 C:\windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)

0x83923000 C:\windows\system32\drivers\nvraid.sys 110592 bytes (NVIDIA Corporation, NVIDIA® nForce RAID Driver)

0x91A1E000 C:\windows\system32\drivers\AtiHdmi.sys 106496 bytes (ATI Research Inc., Ati High Definition Audio Function Driver)

0xAF3A2000 C:\windows\system32\DRIVERS\bthpan.sys 106496 bytes (Microsoft Corporation, Bluetooth Personal Area Networking)

0x83BD3000 C:\windows\system32\drivers\lsi_fc.sys 106496 bytes (LSI Logic, LSI Logic Fusion-MPT FC Driver (StorPort))

0x83BAE000 C:\windows\system32\drivers\lsi_scsi.sys 106496 bytes (LSI Logic, LSI Logic Fusion-MPT SCSI Driver (StorPort))

0x83909000 C:\windows\system32\drivers\msdsm.sys 106496 bytes (Microsoft Corporation, Microsoft Device Specific Module)

0xAB81E000 C:\windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)

0x8C576000 C:\windows\System32\Drivers\SafeBoot.sys 102400 bytes

0x90AC9000 C:\windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0x839A8000 C:\windows\system32\drivers\lsi_sas.sys 98304 bytes (LSI Logic, LSI Logic Fusion-MPT SAS Driver (StorPort))

0xAB8C5000 C:\windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)

0x92F5E000 C:\windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)

0x90B6A000 C:\windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0x8BB17000 C:\windows\system32\drivers\arc.sys 90112 bytes (Adaptec, Inc., Adaptec RAID Storport Driver)

0x8BB2D000 C:\windows\system32\drivers\arcsas.sys 90112 bytes (Adaptec, Inc., Adaptec SAS RAID WS03 Driver)

0xA03E8000 C:\windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)

0x92E87000 C:\windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)

0x91BA3000 C:\windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)

0xAB837000 C:\windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)

0x90BD2000 C:\windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)

0x8C561000 C:\windows\system32\drivers\sbp2port.sys 86016 bytes (Microsoft Corporation, SBP-2 Protocol Driver)

0x8BFA5000 C:\windows\system32\drivers\sisraid4.sys 86016 bytes (Silicon Integrated Systems, SiS AHCI Stor-Miniport Driver)

0x8BB03000 C:\windows\system32\drivers\djsvs.sys 81920 bytes (Adaptec, Inc., Adaptec Ultra SCSI miniport)

0x90BBE000 C:\windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0x91BC3000 C:\windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)

0x90A68000 C:\windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)

0xA0368000 C:\windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)

0x92EAB000 C:\windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xAB96C000 C:\windows\System32\Drivers\SENTINEL.SYS 73728 bytes (Rainbow Technologies, Inc., Sentinel System Driver (NT Parallel driver))

0x8C5CE000 C:\windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)

0x91A0D000 C:\windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)

0x80482000 C:\windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)

0x8BDA8000 C:\windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)

0x92FE6000 C:\windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library)

0x8BBE1000 C:\windows\system32\drivers\iirsp.sys 65536 bytes (Intel Corp./ICP vortex GmbH, Intel/ICP Raid Storport Driver)

0xA0324000 C:\windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)

0x838F9000 C:\windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)

0x90BE7000 C:\windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)

0x8C1ED000 C:\windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)

0x805EB000 C:\windows\system32\drivers\isapnp.sys 61440 bytes (Microsoft Corporation, PNP ISA Bus Driver)

0x92FD7000 C:\windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)

0x8C58F000 C:\windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0x83825000 C:\windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)

0x90BAF000 C:\windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0x8BDC2000 C:\windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0x83841000 C:\windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)

0x9D4E0000 C:\windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)

0x92E9D000 C:\windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)

0x8BCD2000 C:\windows\system32\drivers\nfrd960.sys 57344 bytes (IBM Corporation, IBM ServeRAID Controller Driver)

0x92A00000 C:\windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)

0x838A1000 C:\windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0xAF3C8000 C:\windows\System32\Drivers\BTHUSB.sys 53248 bytes (Microsoft Corporation, Bluetooth Miniport Driver)

0x92FBF000 C:\windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)

0x8BCE0000 C:\windows\system32\drivers\nvstor.sys 53248 bytes (NVIDIA Corporation, NVIDIA® nForce Sata Performance Driver)

0x8BF98000 C:\windows\system32\drivers\sisraid2.sys 53248 bytes (Microsoft Corporation, SiS RAID Stor Miniport Driver)

0x91DAF000 C:\windows\system32\DRIVERS\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0)

0x83A00000 C:\windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)

0x8067E000 C:\windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)

0x8BBF1000 C:\windows\system32\drivers\iteatapi.sys 49152 bytes (Integrated Technology Express, Inc., ITE IT8211 ATA/ATAPI SCSI miniport)

0x8BA00000 C:\windows\system32\drivers\iteraid.sys 49152 bytes (Integrated Technology Express, Inc., ITE IT8212 ATA RAID SCSI miniport)

0x8BFBA000 C:\windows\system32\drivers\symc8xx.sys 49152 bytes (LSI Logic, LSI Logic 8XX SCSI Miniport Driver)

0xAF38C000 C:\windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)

0x92BB7000 C:\windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0x90313000 C:\windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)

0x90B18000 C:\windows\system32\DRIVERS\Accelerometer.sys 45056 bytes (Hewlett-Packard Corporation, HP Accelerometer)

0xAB95E000 C:\Users\ELITSA~1\AppData\Local\Temp\aswMBR.sys 45056 bytes

0x83BC8000 C:\windows\system32\drivers\hpcisss.sys 45056 bytes (Hewlett-Packard Company, Smart Array Storport Driver)

0x90A80000 C:\windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)

0x90ABE000 C:\windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)

0x8BCBD000 C:\windows\system32\drivers\mraid35x.sys 45056 bytes (LSI Logic Corporation, MegaRAID RAID Controller Driver for Windows Vista/Longhorn for x86)

0x92BF4000 C:\windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)

0x90B81000 C:\windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0x8BE00000 C:\windows\System32\Drivers\SbAlg.sys 45056 bytes (SafeBoot N.V., SafeBoot FIPS AES Algorithm (256 bit))

0x8BFC6000 C:\windows\system32\drivers\sym_hi.sys 45056 bytes (LSI Logic, LSI Logic Hi-Perf SCSI Miniport Driver)

0x8BFD1000 C:\windows\system32\drivers\sym_u3.sys 45056 bytes (LSI Logic, LSI Logic Ultra160 SCSI Miniport Driver)

0x90B5F000 C:\windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)

0x8C3EA000 C:\windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)

0x903AC000 C:\windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)

0x91BB9000 C:\windows\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver)

0x83837000 C:\windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)

0xAF398000 C:\windows\system32\DRIVERS\BthEnum.sys 40960 bytes (Microsoft Corporation, Bluetooth Bus Extender)

0xAB954000 C:\windows\system32\DRIVERS\btwl2cap.sys 40960 bytes (Broadcom Corporation., Broadcom Bluetooth L2CAP Service)

0x92FCD000 C:\windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)

0x8BBD7000 C:\windows\system32\drivers\i2omp.sys 40960 bytes (Microsoft Corporation, I2O Miniport Driver)

0x83BED000 C:\windows\system32\drivers\megasas.sys 40960 bytes (LSI Corporation, MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x86)

0x8BCC8000 C:\windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)

0x903F5000 C:\windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)

0xA035E000 C:\windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)

0x92F54000 C:\windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)

0x8BDB8000 C:\windows\System32\Drivers\PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0xAF382000 C:\windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)

0xAF3BF000 C:\windows\system32\DRIVERS\asyncmac.sys 36864 bytes (Microsoft Corporation, MS Remote Access serial network driver)

0x8C5DF000 C:\windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)

0x92B97000 C:\windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)

0x8C5C5000 C:\windows\system32\DRIVERS\hpdskflt.sys 36864 bytes (Hewlett-Packard Corporation, HP Disk Filter - SATA/RAID)

0xA0200000 C:\windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0x92BAE000 C:\windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0x9D4C0000 C:\windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)

0x8C5F6000 C:\windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)

0x90B27000 C:\windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)

0x8078B000 C:\windows\System32\Drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0x83B88000 C:\windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)

0x80493000 C:\windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)

0x838F1000 C:\windows\system32\drivers\cmdide.sys 32768 bytes (CMD Technology, Inc., CMD PCI IDE Bus Driver)

0x805BC000 C:\windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)

0x92BE4000 C:\windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)

0x92BEC000 C:\windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)

0x92EBE000 C:\windows\System32\Drivers\SCDEmu.SYS 32768 bytes (PowerISO Computing, Inc., PowerISO Virtual Drive)

0x8C559000 C:\windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)

0x8395F000 C:\windows\system32\drivers\viaide.sys 32768 bytes (VIA Technologies, Inc., VIA Generic PCI IDE Bus Driver)

0x8C518000 C:\windows\system32\drivers\wd.sys 32768 bytes (Microsoft Corporation, Microsoft Watchdog Timer Driver)

0x838E3000 C:\windows\system32\drivers\aliide.sys 28672 bytes (Acer Laboratories Inc., ALi mini IDE Driver)

0x838EA000 C:\windows\system32\drivers\amdide.sys 28672 bytes (Microsoft Corporation, AMD IDE Driver)

0x92BA7000 C:\windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)

0x92B20000 C:\windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0x8389A000 C:\windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)

0x8040B000 C:\windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0x92BA0000 C:\windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)

0x838AF000 C:\windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)

0x91DBC000 C:\windows\system32\DRIVERS\sncduvc.SYS 28672 bytes (-, USBCAMD for Sonix UVC)

0x92EE8000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS)

0x92E82000 C:\windows\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver)

0x90A7B000 C:\windows\system32\DRIVERS\HpqKbFiltr.sys 20480 bytes (Hewlett-Packard Development Company, L.P., HpqKbFiltr Keyboard Filter Driver)

0x90B23000 C:\windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)

0xA0241000 C:\windows\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver)

0xAF3BC000 C:\windows\system32\DRIVERS\btwrchid.sys 12288 bytes (Broadcom Corporation., Bluetooth Remote Control HID Minidriver)

0x83834000 C:\windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)

0x92EEE000 C:\windows\System32\Drivers\RsvLock.SYS 8192 bytes (SafeBoot International, SafeBoot Reserved Files Lock Driver)

0x8BFFD000 C:\windows\System32\Drivers\SbFsLock.sys 8192 bytes (SafeBoot International, SafeBoot FS Locker)

0x90BF7000 C:\windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0x90ABC000 C:\windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)

0x92FCC000 C:\windows\System32\Drivers\dump_SbHiber.sys 4096 bytes

0x86D501F8 unknown_irp_handler 3592 bytes

0x8B1B21F8 unknown_irp_handler 3592 bytes

0x86D361F8 unknown_irp_handler 3592 bytes

0x86D3E1F8 unknown_irp_handler 3592 bytes

0x86D3B1F8 unknown_irp_handler 3592 bytes

0x86D2E1F8 unknown_irp_handler 3592 bytes

0x86D3F1F8 unknown_irp_handler 3592 bytes

0x86D311F8 unknown_irp_handler 3592 bytes

0x86D451F8 unknown_irp_handler 3592 bytes

0x86D371F8 unknown_irp_handler 3592 bytes

0x88D961F8 unknown_irp_handler 3592 bytes

0x86D471F8 unknown_irp_handler 3592 bytes

0x86D2F1F8 unknown_irp_handler 3592 bytes

0x86D481F8 unknown_irp_handler 3592 bytes

0x86D351F8 unknown_irp_handler 3592 bytes

0x86D411F8 unknown_irp_handler 3592 bytes

0x86D3A1F8 unknown_irp_handler 3592 bytes

0x86D331F8 unknown_irp_handler 3592 bytes

0x86D4C1F8 unknown_irp_handler 3592 bytes

0x86D461F8 unknown_irp_handler 3592 bytes

0x86D491F8 unknown_irp_handler 3592 bytes

0x88C911F8 unknown_irp_handler 3592 bytes

0x86D431F8 unknown_irp_handler 3592 bytes

0x86D3D1F8 unknown_irp_handler 3592 bytes

0x86D341F8 unknown_irp_handler 3592 bytes

0x86D4B1F8 unknown_irp_handler 3592 bytes

0x88D8A1F8 unknown_irp_handler 3592 bytes

0x86D4D1F8 unknown_irp_handler 3592 bytes

0x86D3C1F8 unknown_irp_handler 3592 bytes

0x86D2B1F8 unknown_irp_handler 3592 bytes

0x86D401F8 unknown_irp_handler 3592 bytes

0x86D4F1F8 unknown_irp_handler 3592 bytes

0x86D301F8 unknown_irp_handler 3592 bytes

0x86D321F8 unknown_irp_handler 3592 bytes

0x88C9C1F8 unknown_irp_handler 3592 bytes

0x86D511F8 unknown_irp_handler 3592 bytes

0x86D4A1F8 unknown_irp_handler 3592 bytes

0x86D381F8 unknown_irp_handler 3592 bytes

0x86D4E1F8 unknown_irp_handler 3592 bytes

0x86D391F8 unknown_irp_handler 3592 bytes

0x86D421F8 unknown_irp_handler 3592 bytes

0x86D441F8 unknown_irp_handler 3592 bytes

0xA96AD1F8 unknown_irp_handler 3592 bytes

0x88D341F8 unknown_irp_handler 3592 bytes

0x8ABB4500 unknown_irp_handler 2816 bytes

0x8AD9D500 unknown_irp_handler 2816 bytes

0x88D9A500 unknown_irp_handler 2816 bytes

==============================================

>Stealth

==============================================

0x063A0000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 102400 bytes

0x00780000 Hidden Image-->HP.ActiveSupportLibrary.dll [ EPROCESS 0x867D1D90 ] PID: 6084, 110592 bytes

0x07970000 Hidden Image-->CLI.Component.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 1150976 bytes

0x00450000 Hidden Image-->MOM.Implementation.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 118784 bytes

0x00BA0000 Hidden Image-->MOM.Implementation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 118784 bytes

0x07BE0000 Hidden Image-->CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 135168 bytes

0x07AA0000 Hidden Image-->CLI.Aspect.Welcome.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 151552 bytes

0x08270000 Hidden Image-->CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 159744 bytes

0x07DC0000 Hidden Image-->CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 1699840 bytes

0x07440000 Hidden Image-->CLI.Aspect.InfoCentre.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 217088 bytes

0x07AD0000 Hidden Image-->CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 233472 bytes

0x00AC0000 Hidden Image-->Interop.HPQWMIEXLib.dll [ EPROCESS 0xA2F78D90 ] PID: 2228, 28672 bytes

0x04070000 Hidden Image-->Interop.HPQTOASTERLib.dll [ EPROCESS 0xA2F78D90 ] PID: 2228, 28672 bytes

0x00CA0000 Hidden Image-->MOM.Foundation.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 28672 bytes

0x00D50000 Hidden Image-->LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 28672 bytes

0x00420000 Hidden Image-->MOM.Foundation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x00450000 Hidden Image-->LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x00C00000 Hidden Image-->ResourceManagement.Foundation.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x00C80000 Hidden Image-->CLI.Component.Runtime.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x041E0000 Hidden Image-->Branding.dll [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x04950000 Hidden Image-->AEM.Plugin.Hotkeys.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x04820000 Hidden Image-->AEM.Server.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x04940000 Hidden Image-->AEM.Plugin.DPPE.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x04960000 Hidden Image-->AEM.Plugin.WinMessages.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x04C60000 Hidden Image-->DEM.Foundation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x04D90000 Hidden Image-->DEM.Graphics.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06070000 Hidden Image-->CLI.Component.Runtime.Extension.EEU.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x057E0000 Hidden Image-->DEM.OS.I0602.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x057F0000 Hidden Image-->DEM.OS.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x05840000 Hidden Image-->DEM.Graphics.I0709.dll [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x059E0000 Hidden Image-->AEM.Plugin.GD.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x05EB0000 Hidden Image-->AEM.Actions.CCAA.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x05EC0000 Hidden Image-->DEM.Graphics.I0804.dll [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06010000 Hidden Image-->APM.Foundation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06060000 Hidden Image-->AEM.Plugin.REG.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06130000 Hidden Image-->CLI.Component.Client.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06090000 Hidden Image-->AEM.Plugin.EEU.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06140000 Hidden Image-->CLI.Component.Wizard.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06270000 Hidden Image-->CLI.Caste.Graphics.Wizard.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x063C0000 Hidden Image-->atixclib.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x063F0000 Hidden Image-->CLI.Component.Dashboard.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06400000 Hidden Image-->CLI.Component.Dashboard.Shared.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06670000 Hidden Image-->CLI.Caste.Graphics.Runtime.Shared.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x066E0000 Hidden Image-->DEM.Graphics.I0805.dll [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06830000 Hidden Image-->DEM.Graphics.I0706.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x06E50000 Hidden Image-->CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x070A0000 Hidden Image-->CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x075B0000 Hidden Image-->DEM.Graphics.I0712.dll [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x075C0000 Hidden Image-->DEM.Graphics.I0812.dll [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x07730000 Hidden Image-->CLI.Caste.Graphics.Dashboard.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 28672 bytes

0x05190000 Hidden Image-->CLI.Caste.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 299008 bytes

0x07640000 Hidden Image-->CLI.Aspect.DeviceLCD.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 315392 bytes

0x00AB0000 Hidden Image-->HPWAMain.resources.dll [ EPROCESS 0xA2F78D90 ] PID: 2228, 36864 bytes

0x00E60000 Hidden Image-->NEWAEM.Foundation.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 36864 bytes

0x00E50000 Hidden Image-->CCC.Implementation.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 36864 bytes

0x003E0000 Hidden Image-->CCC.Implementation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x00C60000 Hidden Image-->AxInterop.WBOCXLib.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x00BF0000 Hidden Image-->CLI.Foundation.XManifest.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x03E40000 Hidden Image-->NEWAEM.Foundation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x04190000 Hidden Image-->Interop.WBOCXLib.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x04F70000 Hidden Image-->ACE.Graphics.DisplaysManager.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x06150000 Hidden Image-->CLI.Component.Wizard.Shared.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x066C0000 Hidden Image-->CLI.Aspect.CustomFormats.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x070D0000 Hidden Image-->CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x06E80000 Hidden Image-->CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x07120000 Hidden Image-->CLI.Aspect.DeviceLCD.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x07690000 Hidden Image-->CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 36864 bytes

0x08520000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 372736 bytes

0x060A0000 Hidden Image-->CLI.Component.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 413696 bytes

0x076A0000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 413696 bytes

0x08430000 Hidden Image-->CLI.Aspect.DeviceLCD.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 413696 bytes

WARNING: File locked for read access [C:\windows\system32\drivers\SafeBoot.sys]

WARNING: File locked for read access [C:\windows\system32\drivers\sptd.sys]

0x083C0000 Hidden Image-->CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 446464 bytes

0x00AB0000 Hidden Image-->LOG.Foundation.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 45056 bytes

0x00C90000 Hidden Image-->LOG.Foundation.Private.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 45056 bytes

0x00400000 Hidden Image-->LOG.Foundation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x004D0000 Hidden Image-->LOG.Foundation.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x00CA0000 Hidden Image-->ATICCCom.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x066D0000 Hidden Image-->CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x06E40000 Hidden Image-->CLI.Aspect.DeviceProperty.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x06F90000 Hidden Image-->CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x07110000 Hidden Image-->CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 45056 bytes

0x084A0000 Hidden Image-->CLI.Aspect.DeviceDFP.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 462848 bytes

0x073C0000 Hidden Image-->CLI.Aspect.TransCode.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 503808 bytes

0x04EC0000 Hidden Image-->ResourceManagement.Foundation.Implementation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 512000 bytes

0x00C40000 Hidden Image-->CLI.Component.Runtime.Shared.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x00C50000 Hidden Image-->CLI.Foundation.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x03E30000 Hidden Image-->AEM.Server.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x04930000 Hidden Image-->AEM.Plugin.Source.Kit.Server.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x04D70000 Hidden Image-->DEM.Graphics.I0601.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x06120000 Hidden Image-->CLI.Component.Client.Shared.Private.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x06160000 Hidden Image-->CLI.Caste.Graphics.Wizard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x06290000 Hidden Image-->CLI.Aspect.TransCode.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x066B0000 Hidden Image-->CLI.Aspect.DeviceCV.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x06E70000 Hidden Image-->CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x070E0000 Hidden Image-->CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x07620000 Hidden Image-->CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 53248 bytes

0x08580000 Hidden Image-->CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 602112 bytes

0x07100000 Hidden Image-->CLI.Aspect.DeviceCRT.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 61440 bytes

0x07370000 Hidden Image-->CLI.Aspect.DeviceDFP.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 61440 bytes

0x075A0000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 61440 bytes

0x07610000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 61440 bytes

0x00D10000 Hidden Image-->LOG.Foundation.Implementation.DLL [ EPROCESS 0xAAB735F8 ] PID: 1192, 69632 bytes

0x00460000 Hidden Image-->LOG.Foundation.Implementation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 69632 bytes

0x00BD0000 Hidden Image-->CLI.Component.SkinFactory.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 69632 bytes

0x04F50000 Hidden Image-->CLI.Caste.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 69632 bytes

0x06030000 Hidden Image-->APM.Server.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 69632 bytes

0x07580000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 69632 bytes

0x07B10000 Hidden Image-->CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 724992 bytes

0x06690000 Hidden Image-->CLI.Aspect.DeviceCV.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 77824 bytes

0x06810000 Hidden Image-->CLI.Aspect.DeviceTV.Graphics.Shared.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 77824 bytes

0x07350000 Hidden Image-->CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 77824 bytes

0x086F0000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 823296 bytes

0x00430000 Hidden Image-->CLI.Foundation.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 86016 bytes

0x00C20000 Hidden Image-->CLI.Component.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 86016 bytes

0x066F0000 Hidden Image-->CLI.Aspect.DeviceTV.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 86016 bytes

0x07710000 Hidden Image-->CLI.Caste.Graphics.Dashboard.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 86016 bytes

0x05E90000 Hidden Image-->ATIDEMOS.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 94208 bytes

0x075E0000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Runtime.DLL [ EPROCESS 0x8650E788 ] PID: 5424, 94208 bytes

==============================================

>Files

==============================================

==============================================

>Hooks

==============================================

ntkrnlpa.exe+0x000A87AA, Type: Inline - RelativeJump 0x82EB37AA-->82EB37B1 [ntkrnlpa.exe]

ntkrnlpa.exe+0x000AC954, Type: Inline - RelativeJump 0x82EB7954-->82EB7926 [ntkrnlpa.exe]

ntkrnlpa.exe+0x000AC978, Type: Inline - RelativeJump 0x82EB7978-->82EB7945 [ntkrnlpa.exe]

ntkrnlpa.exe-->NtCreateProcessEx, Type: Inline - RelativeJump 0x8309CDAE-->92F94906 [aswSP.SYS]

ntkrnlpa.exe-->ObInsertObject, Type: Inline - RelativeJump 0x8303B4F3-->92F91D5C [aswSP.SYS]

ntkrnlpa.exe-->ObMakeTemporaryObject, Type: Inline - RelativeJump 0x82FE25C7-->92F902BE [aswSP.SYS]

[1052]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1052]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1052]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1052]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1052]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1052]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1052]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1052]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1052]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1084]AtService.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1084]AtService.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1084]AtService.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1084]AtService.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1084]AtService.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1084]AtService.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1084]AtService.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1084]AtService.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1100]HPFSService.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1132]HpFkCrypt.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1160]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1160]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1160]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1160]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1160]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1160]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1160]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1160]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1204]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1204]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1204]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1204]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1204]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1204]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1204]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1204]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1236]SynTPHelper.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1260]AEADISRV.EXE-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1292]Ati2evxx.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1320]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1320]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1320]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1320]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1320]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1320]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1320]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1320]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1348]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1348]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1348]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1348]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1348]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1348]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1348]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1348]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1360]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1360]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1360]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1360]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1360]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1360]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1360]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1360]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1368]raysat_3dsmax2010_32server.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1448]PsiService_2.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1460]LSSrvc.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1520]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1520]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1520]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1596]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1596]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1596]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1596]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1596]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1596]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1596]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1596]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1716]dwm.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1716]dwm.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1716]dwm.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1716]dwm.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1716]dwm.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1716]dwm.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1716]dwm.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1716]dwm.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1724]acevents.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1724]acevents.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1724]acevents.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1724]acevents.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1724]acevents.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1724]acevents.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1724]acevents.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1724]acevents.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1732]hpservice.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1732]hpservice.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1732]hpservice.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1732]hpservice.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1732]hpservice.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1732]hpservice.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1732]hpservice.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1732]hpservice.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1800]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1800]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1800]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1800]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1800]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1800]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1800]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1800]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1828]asghost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1828]asghost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1828]asghost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1828]asghost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1828]asghost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1828]asghost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1828]asghost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1828]asghost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[1952]AvastSvc.exe-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - PushRet 0x7772A84F-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[1976]Ati2evxx.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2024]pdfsvc.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2128]MSASCui.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2160]IAAnotif.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2172]accrdsub.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2184]pthosttr.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2208]SynTPEnh.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2444]CoreShredder.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2452]QLBCtrl.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2476]hpwuSchd2.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2780]acevents.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2780]acevents.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2780]acevents.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2780]acevents.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2780]acevents.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2780]acevents.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2780]acevents.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2780]acevents.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2800]ApplicationUpdater.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2816]GrooveMonitor.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2844]taskeng.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2844]taskeng.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2844]taskeng.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2844]taskeng.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2844]taskeng.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2844]taskeng.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2844]taskeng.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2844]taskeng.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2888]spoolsv.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2912]smax4pnp.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2932]issch.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]

[2932]issch.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2932]issch.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [shimeng.dll]

[2932]issch.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x0040E020-->00000000 [shimeng.dll]

[2932]issch.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2932]issch.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2932]issch.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x768E1414-->00000000 [shimeng.dll]

[2932]issch.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]

[2932]issch.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2932]issch.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2932]issch.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2932]issch.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2932]issch.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2932]issch.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [shimeng.dll]

[2948]VolCtrl.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2948]VolCtrl.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[2960]PWRISOVM.EXE-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3020]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3020]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3020]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3080]SearchSettings.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3136]mDNSResponder.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3140]taskeng.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3140]taskeng.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3140]taskeng.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3140]taskeng.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3140]taskeng.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3140]taskeng.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3140]taskeng.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3140]taskeng.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3176]btwdins.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3176]btwdins.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3176]btwdins.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3176]btwdins.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3176]btwdins.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3176]btwdins.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3176]btwdins.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3176]btwdins.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3212]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3212]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3212]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3212]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3212]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3212]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3212]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3212]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3292]sidebar.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3292]sidebar.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3292]sidebar.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3292]sidebar.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3292]sidebar.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3292]sidebar.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3292]sidebar.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3292]sidebar.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3316]LightScribeControlPanel.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3448]wuauclt.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3460]ehtray.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3460]ehtray.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3460]ehtray.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3460]ehtray.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3460]ehtray.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3460]ehtray.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3460]ehtray.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3460]ehtray.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3548]btdna.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3548]btdna.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3548]btdna.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3548]btdna.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3548]btdna.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3548]btdna.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3548]btdna.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3548]btdna.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3576]daemon.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3576]daemon.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3576]daemon.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3576]daemon.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3576]daemon.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3576]daemon.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3576]daemon.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3576]daemon.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3692]sidebar.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3692]sidebar.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3692]sidebar.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3692]sidebar.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3692]sidebar.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3692]sidebar.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3692]sidebar.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3692]sidebar.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3740]ehmsas.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[376]explorer.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[376]explorer.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[376]explorer.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[376]explorer.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[376]explorer.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[376]explorer.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[376]explorer.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[376]explorer.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3780]olycamdetect.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3844]bittorrent.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3888]SUPERAntiSpyware.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[3972]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[3972]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[3972]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[3972]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[3972]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[3972]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[3972]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[3972]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4012]accoca.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4012]accoca.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4012]accoca.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4012]accoca.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4012]accoca.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4012]accoca.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4012]accoca.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4012]accoca.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4052]BTTray.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4052]BTTray.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4052]BTTray.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4052]BTTray.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4052]BTTray.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4052]BTTray.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4052]BTTray.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4052]BTTray.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4120]lmgrd.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4136]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4136]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4136]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4168]lmgrd.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4180]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4180]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4180]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4212]SearchIndexer.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4328]CNAB4RPK.EXE-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4396]BTStackServer.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4468]IAANTmon.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[4796]hpqWmiEx.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[5024]FlashUtil10n_ActiveX.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[5348]WmiPrvSE.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[5816]Com4QLBEx.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[5844]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61130-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B6119C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B611BC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B6111C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61110-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B61174-->00000000 [iEShims.dll]

[5844]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B611AC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6D64123C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[5844]iexplore.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[5844]iexplore.exe-->shell32.dll+0x0006BA64, Type: Inline - RelativeJump 0x75F1BA64-->00000000 [shell32.dll]

[5844]iexplore.exe-->shell32.dll+0x0006BA94, Type: Inline - RelativeJump 0x75F1BA94-->00000000 [shell32.dll]

[5844]iexplore.exe-->shell32.dll+0x0006BBF0, Type: Inline - RelativeJump 0x75F1BBF0-->00000000 [shell32.dll]

[5844]iexplore.exe-->shell32.dll+0x000887E0, Type: Inline - RelativeJump 0x75F387E0-->00000000 [shell32.dll]

[5844]iexplore.exe-->shell32.dll+0x00088938, Type: Inline - RelativeJump 0x75F38938-->00000000 [shell32.dll]

[5844]iexplore.exe-->shell32.dll+0x000889B0, Type: Inline - RelativeJump 0x75F389B0-->00000000 [shell32.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x768E125C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x768E13B0-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x768E1460-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x768E11A4-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x768E12E8-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x768E13B4-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x768E132C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x768E1328-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x768E1114-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x768E1280-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x768E1370-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x768E14A4-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x768E13BC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x768E14EC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x768E1390-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x768E1164-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x768E1100-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x768E13A0-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x768E136C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x768E1428-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x768E14E0-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x768E1284-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x768E1448-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x768E13C0-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x768E130C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x768E13AC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x768E1140-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x768E1384-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x768E124C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x768E13B8-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x768E1168-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x768E116C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x768E2320-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x768E1890-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x768E1A6C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x768E191C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x76F58E3B-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x76F726F1-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x76F79A62-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x76F717AA-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x76F572A2-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x76F61305-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x76F9847D-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76F82EF5-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x76F98152-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x76F810B0-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x76F5CD8B-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x76F8326E-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x76F5863C-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x76F68CB1-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x76F71847-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x76F70745-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [iEShims.dll]

[5844]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x76FAD972-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x76FAD639-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x76FAD65D-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x76FAD4D9-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x76FAD5D3-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x76F82F75-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x76F96FB2-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x76F80987-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[5844]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[5844]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [ieframe.dll]

[5844]iexplore.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[5844]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [iEShims.dll]

[5844]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [iEShims.dll]

[5856]HpqToaster.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[5856]HpqToaster.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[6060]unsecapp.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[728]wininit.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[728]wininit.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[728]wininit.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[728]wininit.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[728]wininit.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[728]wininit.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[728]wininit.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[728]wininit.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[7580]ugslmd.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[768]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[768]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[768]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[772]services.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[772]services.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[772]services.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[772]services.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[772]services.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[772]services.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[772]services.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[772]services.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[784]lsass.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[784]lsass.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[784]lsass.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[784]lsass.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[784]lsass.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[784]lsass.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[784]lsass.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[784]lsass.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[792]lsm.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[792]lsm.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[792]lsm.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[8120]iexplore.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[8120]iexplore.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[8120]iexplore.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[8120]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x76F61305-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x76F9847D-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76F82EF5-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x76F98152-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x76F810B0-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x76FAD639-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x76FAD65D-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x76FAD4D9-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x76FAD5D3-->00000000 [ieframe.dll]

[8120]iexplore.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[8120]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[8120]iexplore.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[8120]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[8120]iexplore.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[880]winlogon.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[880]winlogon.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[880]winlogon.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[880]winlogon.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[880]winlogon.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[880]winlogon.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[880]winlogon.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[880]winlogon.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->ChangeServiceConfig2A, Type: Inline - RelativeJump 0x76B47099-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->ChangeServiceConfig2W, Type: Inline - RelativeJump 0x76B471E1-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->ChangeServiceConfigA, Type: Inline - RelativeJump 0x76B46DD9-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->ChangeServiceConfigW, Type: Inline - RelativeJump 0x76B46F81-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x76B472A1-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x76B09EB4-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->DeleteService, Type: Inline - RelativeJump 0x76B0A07E-->00000000 [unknown_code_page]

[988]svchost.exe-->advapi32.dll-->SetServiceObjectSecurity, Type: Inline - RelativeJump 0x76B46CD9-->00000000 [unknown_code_page]

[988]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x778393A8-->00000000 [unknown_code_page]

[988]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7784B740-->00000000 [unknown_code_page]

[988]svchost.exe-->user32.dll-->SetWindowsHookExA, Type: Inline - RelativeJump 0x76F56322-->00000000 [unknown_code_page]

[988]svchost.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x76F587AD-->00000000 [unknown_code_page]

[988]svchost.exe-->user32.dll-->SetWinEventHook, Type: Inline - RelativeJump 0x76F59F3A-->00000000 [unknown_code_page]

[988]svchost.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x76F598DB-->00000000 [unknown_code_page]

[988]svchost.exe-->user32.dll-->UnhookWinEvent, Type: Inline - RelativeJump 0x76F5C06F-->00000000 [unknown_code_page]

По-принцип проблема със скритите файлове и папки се решава лесно...просто мога да ви кажа как да не ги виждате повече, но зависи дали са били скрити от гадината.

Имате ли липсващи икони в Start Menu-то...и има ли скрити икони на програми по десктопа...(такива които са били инсталирани преди да почнем да почистваме).

Относно ASWmbr, стартирайте файла с десен бутон върху него => Run As administrator и вижте дали бутона SCAN вече е активен.

Невиждам липсващи програми, а скритите иконки на десктопа са само тези, които съм приложила като картинки, никоя не е на програма инсталирана преди

Scan бутонът продължава да не е активен

Здравейте,

desktop.ini иконите са нормални.

Те съдържат информация за това как да изглежда дадена икона на десктопа и друга информация.

Можете да ги изтриете, но така ще се загуби дадена customize-ация ако сте правили такива.

Останалите *.doc файлове трябва сами да решите дали да изтриете. Преди обаче да ги отворите не е зле да изчакате да завърши проверката с ESET за всеки случай.

~WRL320... => идея си нямам какво е...но е файл без разширение (ако се съди по иконата му), така че мисля, че не е проблем да се изтрие.

Останалите икони които не са на десктопа и са скрити са различни системни икони и папки...не ги пиптайте !!! За да не ги виждате повече направете следното:

Отидете в My Computer => Tools => Folder Options => View => сложете отметка пред "Hide protected-operating system files (recommended)" и потвърдете с Apply.

Системните файлове трябва да са скрити сега.

Публикувано изображение

По въпроса с ASWmbr, нека да използваме алтернативна програма...за да съм сигурен, че всичко е ок...(не забравяйте, че чакам и резултатите от Eset).

  • Изтеглете TDSSKiller и го разархивирайте на десктопa.

  • Стартирайте TDSSKiller.exe, след това натиснете бутона Start Scan.

    Публикувано изображение

  • Ако бъде открит зловреден (malicious) файл, проверете дали е избрана опцията Cure (по подразбиране). Ако е избрана Cure - натиснете Continue

    Публикувано изображение

  • Ако бъде открит подозрителен (suspicious) файл, проверете дали е избрана опцията Skip (по подразбиране). Ако е избрана Skip - натиснете Continue.

  • Изберете skip и за sptd услугата:

    Публикувано изображение

  • Възможно е програмата да изиска рестарт. Ако е така - потвърдете с Reboot Now.

    Публикувано изображение

    -Ако няма рестартиране, отидете на Report. Ще се появи лог файл. Копирайте и поставете съдържанието му в следващия си коментар.

    -Ако има рестартиране, отидете на в основаната директория на дял C:\. Там трябва да има файл с формат: TDSSKiller.[Version]_[Date]_[Time]_log.txt. Отворете го, копирайте и поставете съдържанието му в следващия си коментар.

  • Автор

В момента ESET сканира, наложи се да го прекъсна първия път, тъй като му отнема доста време, а трябваше да напусна офиса и да се прибера. Сега ще го оставя да довърши сканирането - до момента е открил 8 гадинки, ще публикувам резултата и чак тогава ще пусна и TDSSKIler.

  • Автор

Резултат от сканирането: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=ae270025386e9d4d87ea225794424164 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-06-17 03:00:32 # local_time=2011-06-17 06:00:32 (+0200, FLE Daylight Time) # country="Bulgaria" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=768 16777215 100 0 8919982 8919982 0 0 # compatibility_mode=5892 16776573 100 100 7630 145849694 0 0 # compatibility_mode=8192 67108863 100 0 2523 2523 0 0 # scanned=196510 # found=8 # cleaned=0 # scan_time=5865 C:\Program Files\Application Updater\ApplicationUpdater.exe probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\DealioToolbarFF.dll probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\SolidWorks\patch_sldappu.exe Win32/Tool.Embryo.A application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\YouTube Downloader Toolbar\IE\4.4\youtubedownloaderToolbarIE.dll a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Programi\AUTODESK.3DSMAX.V2010-ISO\3dsmax2010.iso a variant of Win32/Keygen.BL application (unable to clean) 00000000000000000000000000000000 I C:\Programi\Farm Frenzy 3\FarmFrenzy3.exe a variant of Win32/Kryptik.GTW trojan (unable to clean) 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=ae270025386e9d4d87ea225794424164 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-06-17 07:53:05 # local_time=2011-06-17 10:53:05 (+0200, FLE Daylight Time) # country="Bulgaria" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=768 16777215 100 0 8933864 8933864 0 0 # compatibility_mode=5892 16776573 100 100 21512 145863576 0 0 # compatibility_mode=8192 67108863 100 0 16405 16405 0 0 # scanned=292037 # found=11 # cleaned=0 # scan_time=9537 C:\Program Files\Application Updater\ApplicationUpdater.exe probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\DealioToolbarFF.dll probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\SolidWorks\patch_sldappu.exe Win32/Tool.Embryo.A application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\YouTube Downloader Toolbar\IE\4.4\youtubedownloaderToolbarIE.dll a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Programi\AUTODESK.3DSMAX.V2010-ISO\3dsmax2010.iso a variant of Win32/Keygen.BL application (unable to clean) 00000000000000000000000000000000 I C:\Programi\Farm Frenzy 3\FarmFrenzy3.exe a variant of Win32/Kryptik.GTW trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\Elitsa Danailova\Downloads\PowerISO v3.9\Keygen\Keygen.exe.mwt a variant of Win32/Keygen.AF application (unable to clean) 00000000000000000000000000000000 I C:\Users\Elitsa Danailova\Downloads\Wondershare Video Converter Platinum v4.4.4\Keygen\Keygen.exe a variant of Win32/Keygen.AT application (unable to clean) 00000000000000000000000000000000 I ${Memory} a variant of Win32/Adware.Toolbar.Dealio application 00000000000000000000000000000000 I

Здравейте,

От Control Panel-a => Programs => Uninstall a program => деинсталирайте следните приложения:

YouTube Downloader 2.7.1

YouTube Downloader Toolbar v4.4

Dealio Toolbar v4.0.1

Farm Frenzy 3

Farm Frenzy 3 Russian Roulette 1.00

(можете да си инсталирате последната версия на YouTube Downloader 3.0).

При мен тя се инсталира без никакви туулбари...

Cтартирайте пак OTL и с Copy/ Paste под колонката Custom Scans/Fixes въведете скриптовия текст от текстовото поле по-долу, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта!

:OTL
SRV - [2011.05.06 17:33:00 | 000,393,112 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
IE - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.4\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
[2010.02.19 23:31:04 | 000,002,234 | ---- | M] () -- C:\Users\Elitsa Danailova\AppData\Roaming\Mozilla\Firefox\Profiles\uery3fak.default\searchplugins\askcom.xml
[2009.10.17 19:54:35 | 000,000,000 | ---D | M] (Dealio Toolbar Plugin) -- C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
O2 - BHO: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.4\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.4\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
:files
C:\Program Files\YouTube Downloader Toolbar
C:\Program Files\Common Files\Spigot
C:\Program Files\Application Updater
C:\Program Files\Dealio Toolbar
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\DealioToolbarFF.dll
C:\Program Files\SolidWorks\patch_sldappu.exe
C:\Programi\Farm Frenzy 3
:commands
[emptytemp]
[reboot]
След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Публикувано изображение

Ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

PS: Ако не се появи лог файл, отворете папката C:\_OTL\MovedFiles отворете лог файла и публикувайте съдържанието му в следващия си пост.

След това очаквам лог файла от TDSSKiller-a и приключваме. :wors:

  • Автор

Привет! Когато дадох Run fix на OTL всички икони и таскбара изчезнаха, малко по-късно OTL дьде OTL stoped working или нещо такова и се затвори. Наложи се да рестартирам, при което всичко си дойде на мястото като се отвори и лог файла. Не съм сигурна, че всичко е протекло и завършило нормално но ето резултата: Files\Folders moved on Reboot... File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot... Ето и съдържанието на лог файла от сканирането с TDSSkiller: 2011/06/18 18:52:17.0438 1472 TDSS rootkit removing tool 2.5.5.0 Jun 16 2011 15:25:15 2011/06/18 18:52:17.0678 1472 ================================================================================ 2011/06/18 18:52:17.0678 1472 SystemInfo: 2011/06/18 18:52:17.0678 1472 2011/06/18 18:52:17.0678 1472 OS Version: 6.0.6002 ServicePack: 2.0 2011/06/18 18:52:17.0678 1472 Product type: Workstation 2011/06/18 18:52:17.0678 1472 ComputerName: ELI4KA-PC 2011/06/18 18:52:17.0678 1472 UserName: Elitsa Danailova 2011/06/18 18:52:17.0678 1472 Windows directory: C:\windows 2011/06/18 18:52:17.0678 1472 System windows directory: C:\windows 2011/06/18 18:52:17.0678 1472 Processor architecture: Intel x86 2011/06/18 18:52:17.0678 1472 Number of processors: 2 2011/06/18 18:52:17.0678 1472 Page size: 0x1000 2011/06/18 18:52:17.0678 1472 Boot type: Normal boot 2011/06/18 18:52:17.0678 1472 ================================================================================ 2011/06/18 18:52:18.0128 1472 Initialize success 2011/06/18 18:52:29.0929 5892 ================================================================================ 2011/06/18 18:52:29.0929 5892 Scan started 2011/06/18 18:52:29.0929 5892 Mode: Manual; 2011/06/18 18:52:29.0929 5892 ================================================================================ 2011/06/18 18:52:30.0419 5892 Accelerometer (aef9ee4451d5c46370142cb06d0f3591) C:\windows\system32\DRIVERS\Accelerometer.sys 2011/06/18 18:52:30.0519 5892 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\windows\system32\drivers\acpi.sys 2011/06/18 18:52:30.0619 5892 ADIHdAudAddService (9af9890a9a1d8558e4353942f0713b15) C:\windows\system32\drivers\ADIHdAud.sys 2011/06/18 18:52:30.0709 5892 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\windows\system32\drivers\adp94xx.sys 2011/06/18 18:52:30.0729 5892 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\windows\system32\drivers\adpahci.sys 2011/06/18 18:52:30.0759 5892 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\windows\system32\drivers\adpu160m.sys 2011/06/18 18:52:30.0779 5892 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\windows\system32\drivers\adpu320.sys 2011/06/18 18:52:30.0909 5892 AFD (3911b972b55fea0478476b2e777b29fa) C:\windows\system32\drivers\afd.sys 2011/06/18 18:52:31.0009 5892 AgereSoftModem (35c391e40471a0b479328fc7b1b5f40f) C:\windows\system32\DRIVERS\AGRSM.sys 2011/06/18 18:52:31.0139 5892 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\windows\system32\drivers\agp440.sys 2011/06/18 18:52:31.0169 5892 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\windows\system32\drivers\djsvs.sys 2011/06/18 18:52:31.0199 5892 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\windows\system32\drivers\aliide.sys 2011/06/18 18:52:31.0259 5892 amdagp (c47344bc706e5f0b9dce369516661578) C:\windows\system32\drivers\amdagp.sys 2011/06/18 18:52:31.0269 5892 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\windows\system32\drivers\amdide.sys 2011/06/18 18:52:31.0299 5892 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\windows\system32\drivers\amdk7.sys 2011/06/18 18:52:31.0329 5892 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\windows\system32\DRIVERS\amdk8.sys 2011/06/18 18:52:31.0399 5892 arc (5d2888182fb46632511acee92fdad522) C:\windows\system32\drivers\arc.sys 2011/06/18 18:52:31.0529 5892 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\windows\system32\drivers\arcsas.sys 2011/06/18 18:52:31.0649 5892 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\windows\system32\drivers\aswFsBlk.sys 2011/06/18 18:52:31.0729 5892 aswMonFlt (9bdc8e9ce17b773f69d2c6696c768c4f) C:\windows\system32\drivers\aswMonFlt.sys 2011/06/18 18:52:31.0799 5892 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\windows\system32\drivers\aswRdr.sys 2011/06/18 18:52:31.0889 5892 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\windows\system32\drivers\aswSnx.sys 2011/06/18 18:52:31.0919 5892 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\windows\system32\drivers\aswSP.sys 2011/06/18 18:52:31.0999 5892 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\windows\system32\drivers\aswTdi.sys 2011/06/18 18:52:32.0069 5892 AsyncMac (53b202abee6455406254444303e87be1) C:\windows\system32\DRIVERS\asyncmac.sys 2011/06/18 18:52:32.0129 5892 atapi (2d9c903dc76a66813d350a562de40ed9) C:\windows\system32\drivers\atapi.sys 2011/06/18 18:52:32.0220 5892 AtiHdmiService (d7672d90ef03d0e2efdb02df5045a359) C:\windows\system32\drivers\AtiHdmi.sys 2011/06/18 18:52:32.0345 5892 atikmdag (64895a6443d147c1aba523589b485e02) C:\windows\system32\DRIVERS\atikmdag.sys 2011/06/18 18:52:32.0579 5892 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\windows\system32\DRIVERS\b57nd60x.sys 2011/06/18 18:52:32.0660 5892 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\windows\system32\drivers\Beep.sys 2011/06/18 18:52:32.0740 5892 blbdrive (d4df28447741fd3d953526e33a617397) C:\windows\system32\drivers\blbdrive.sys 2011/06/18 18:52:32.0810 5892 bowser (35f376253f687bde63976ccb3f2108ca) C:\windows\system32\DRIVERS\bowser.sys 2011/06/18 18:52:32.0890 5892 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\drivers\brfiltlo.sys 2011/06/18 18:52:32.0920 5892 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\drivers\brfiltup.sys 2011/06/18 18:52:32.0980 5892 Brserid (b304e75cff293029eddf094246747113) C:\windows\system32\drivers\brserid.sys 2011/06/18 18:52:33.0040 5892 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\system32\drivers\brserwdm.sys 2011/06/18 18:52:33.0060 5892 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\system32\drivers\brusbmdm.sys 2011/06/18 18:52:33.0080 5892 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\system32\drivers\brusbser.sys 2011/06/18 18:52:33.0170 5892 BthEnum (6d39c954799b63ba866910234cf7d726) C:\windows\system32\DRIVERS\BthEnum.sys 2011/06/18 18:52:33.0230 5892 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\windows\system32\drivers\bthmodem.sys 2011/06/18 18:52:33.0280 5892 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\windows\system32\DRIVERS\bthpan.sys 2011/06/18 18:52:33.0360 5892 BTHPORT (5a3abaa2f8eece7aefb942773766e3db) C:\windows\system32\Drivers\BTHport.sys 2011/06/18 18:52:33.0420 5892 BTHUSB (94e2941280e3756a5e0bcb467865c43a) C:\windows\system32\Drivers\BTHUSB.sys 2011/06/18 18:52:33.0500 5892 btwaudio (cd956dd816d9959748eb787a5121d1e4) C:\windows\system32\drivers\btwaudio.sys 2011/06/18 18:52:33.0590 5892 btwavdt (4ca1cc3d13466a3e2e9e9119d00aec78) C:\windows\system32\drivers\btwavdt.sys 2011/06/18 18:52:33.0670 5892 btwl2cap (54c2ee0a3cec586629035d771aacae67) C:\windows\system32\DRIVERS\btwl2cap.sys 2011/06/18 18:52:33.0720 5892 btwrchid (f857ef2d941530772ae828ecd6d71b22) C:\windows\system32\DRIVERS\btwrchid.sys 2011/06/18 18:52:33.0810 5892 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\windows\system32\DRIVERS\cdfs.sys 2011/06/18 18:52:33.0870 5892 cdrom (6b4bffb9becd728097024276430db314) C:\windows\system32\DRIVERS\cdrom.sys 2011/06/18 18:52:33.0950 5892 circlass (e5d4133f37219dbcfe102bc61072589d) C:\windows\system32\drivers\circlass.sys 2011/06/18 18:52:34.0020 5892 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\windows\system32\CLFS.sys 2011/06/18 18:52:34.0200 5892 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\windows\system32\DRIVERS\CmBatt.sys 2011/06/18 18:52:34.0220 5892 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\windows\system32\drivers\cmdide.sys 2011/06/18 18:52:34.0270 5892 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\windows\system32\DRIVERS\compbatt.sys 2011/06/18 18:52:34.0320 5892 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\windows\system32\drivers\crcdisk.sys 2011/06/18 18:52:34.0340 5892 Crusoe (1f07becdca750766a96cda811ba86410) C:\windows\system32\drivers\crusoe.sys 2011/06/18 18:52:34.0440 5892 DAMDrv (dd5682ba88543608612245fb7c06d5e0) C:\windows\system32\DRIVERS\DAMDrv.sys 2011/06/18 18:52:34.0500 5892 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\windows\system32\Drivers\dfsc.sys 2011/06/18 18:52:34.0610 5892 disk (5d4aefc3386920236a548271f8f1af6a) C:\windows\system32\drivers\disk.sys 2011/06/18 18:52:34.0700 5892 drmkaud (97fef831ab90bee128c9af390e243f80) C:\windows\system32\drivers\drmkaud.sys 2011/06/18 18:52:34.0770 5892 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\windows\System32\drivers\dxgkrnl.sys 2011/06/18 18:52:34.0830 5892 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\windows\system32\DRIVERS\E1G60I32.sys 2011/06/18 18:52:34.0920 5892 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\windows\system32\drivers\ecache.sys 2011/06/18 18:52:35.0010 5892 elxstor (23b62471681a124889978f6295b3f4c6) C:\windows\system32\drivers\elxstor.sys 2011/06/18 18:52:35.0090 5892 ErrDev (3db974f3935483555d7148663f726c61) C:\windows\system32\drivers\errdev.sys 2011/06/18 18:52:35.0180 5892 exfat (22b408651f9123527bcee54b4f6c5cae) C:\windows\system32\drivers\exfat.sys 2011/06/18 18:52:35.0210 5892 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\windows\system32\drivers\fastfat.sys 2011/06/18 18:52:35.0240 5892 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\windows\system32\DRIVERS\fdc.sys 2011/06/18 18:52:35.0270 5892 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\windows\system32\drivers\fileinfo.sys 2011/06/18 18:52:35.0300 5892 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\windows\system32\drivers\filetrace.sys 2011/06/18 18:52:35.0370 5892 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\windows\system32\DRIVERS\flpydisk.sys 2011/06/18 18:52:35.0410 5892 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\windows\system32\drivers\fltmgr.sys 2011/06/18 18:52:35.0520 5892 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\windows\system32\drivers\Fs_Rec.sys 2011/06/18 18:52:35.0550 5892 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\windows\system32\drivers\gagp30kx.sys 2011/06/18 18:52:35.0680 5892 Hardlock (d64a40b94602158e40527ae95e7a9193) C:\windows\system32\drivers\hardlock.sys 2011/06/18 18:52:35.0790 5892 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\windows\system32\drivers\HdAudio.sys 2011/06/18 18:52:35.0850 5892 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\windows\system32\DRIVERS\HDAudBus.sys 2011/06/18 18:52:35.0910 5892 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\windows\system32\drivers\hidbth.sys 2011/06/18 18:52:35.0950 5892 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\windows\system32\drivers\hidir.sys 2011/06/18 18:52:36.0000 5892 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\windows\system32\DRIVERS\hidusb.sys 2011/06/18 18:52:36.0110 5892 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\windows\system32\drivers\hpcisss.sys 2011/06/18 18:52:36.0190 5892 hpdskflt (64637b65c90df48c94bb9346afb3ac61) C:\windows\system32\DRIVERS\hpdskflt.sys 2011/06/18 18:52:36.0290 5892 HPFXBULK (e4e0b356a8756066cf89080d9da69f22) C:\windows\system32\drivers\hpfxbulk.sys 2011/06/18 18:52:36.0390 5892 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\windows\system32\DRIVERS\HpqKbFiltr.sys 2011/06/18 18:52:36.0470 5892 HTTP (f870aa3e254628ebeafe754108d664de) C:\windows\system32\drivers\HTTP.sys 2011/06/18 18:52:36.0520 5892 i2omp (c6b032d69650985468160fc9937cf5b4) C:\windows\system32\drivers\i2omp.sys 2011/06/18 18:52:36.0610 5892 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\windows\system32\DRIVERS\i8042prt.sys 2011/06/18 18:52:36.0680 5892 iaStor (baabb0301949774a66b955c65319635a) C:\windows\system32\drivers\iastor.sys 2011/06/18 18:52:36.0710 5892 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\windows\system32\drivers\iastorv.sys 2011/06/18 18:52:36.0730 5892 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\windows\system32\drivers\iirsp.sys 2011/06/18 18:52:36.0880 5892 intelide (83aa759f3189e6370c30de5dc5590718) C:\windows\system32\drivers\intelide.sys 2011/06/18 18:52:37.0000 5892 intelppm (224191001e78c89dfa78924c3ea595ff) C:\windows\system32\DRIVERS\intelppm.sys 2011/06/18 18:52:37.0080 5892 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\windows\system32\DRIVERS\ipfltdrv.sys 2011/06/18 18:52:37.0130 5892 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\windows\system32\drivers\ipmidrv.sys 2011/06/18 18:52:37.0160 5892 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\windows\system32\DRIVERS\ipnat.sys 2011/06/18 18:52:37.0180 5892 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\windows\system32\drivers\irenum.sys 2011/06/18 18:52:37.0210 5892 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\windows\system32\drivers\isapnp.sys 2011/06/18 18:52:37.0260 5892 iScsiPrt (232fa340531d940aac623b121a595034) C:\windows\system32\DRIVERS\msiscsi.sys 2011/06/18 18:52:37.0280 5892 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\windows\system32\drivers\iteatapi.sys 2011/06/18 18:52:37.0300 5892 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\windows\system32\drivers\iteraid.sys 2011/06/18 18:52:37.0340 5892 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\windows\system32\DRIVERS\kbdclass.sys 2011/06/18 18:52:37.0360 5892 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\windows\system32\drivers\kbdhid.sys 2011/06/18 18:52:37.0400 5892 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\windows\system32\Drivers\ksecdd.sys 2011/06/18 18:52:37.0480 5892 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\windows\system32\DRIVERS\lltdio.sys 2011/06/18 18:52:37.0510 5892 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\windows\system32\drivers\lsi_fc.sys 2011/06/18 18:52:37.0550 5892 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\windows\system32\drivers\lsi_sas.sys 2011/06/18 18:52:37.0560 5892 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\windows\system32\drivers\lsi_scsi.sys 2011/06/18 18:52:37.0580 5892 luafv (8f5c7426567798e62a3b3614965d62cc) C:\windows\system32\drivers\luafv.sys 2011/06/18 18:52:37.0620 5892 megasas (0001ce609d66632fa17b84705f658879) C:\windows\system32\drivers\megasas.sys 2011/06/18 18:52:37.0670 5892 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\windows\system32\drivers\megasr.sys 2011/06/18 18:52:37.0820 5892 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\windows\system32\drivers\modem.sys 2011/06/18 18:52:37.0860 5892 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\windows\system32\DRIVERS\monitor.sys 2011/06/18 18:52:37.0920 5892 mouclass (5bf6a1326a335c5298477754a506d263) C:\windows\system32\DRIVERS\mouclass.sys 2011/06/18 18:52:37.0980 5892 mouhid (93b8d4869e12cfbe663915502900876f) C:\windows\system32\DRIVERS\mouhid.sys 2011/06/18 18:52:38.0020 5892 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\windows\system32\drivers\mountmgr.sys 2011/06/18 18:52:38.0080 5892 mpio (511d011289755dd9f9a7579fb0b064e6) C:\windows\system32\drivers\mpio.sys 2011/06/18 18:52:38.0150 5892 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\windows\system32\drivers\mpsdrv.sys 2011/06/18 18:52:38.0240 5892 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\windows\system32\drivers\mraid35x.sys 2011/06/18 18:52:38.0270 5892 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\windows\system32\drivers\mrxdav.sys 2011/06/18 18:52:38.0320 5892 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\windows\system32\DRIVERS\mrxsmb.sys 2011/06/18 18:52:38.0360 5892 mrxsmb10 (d4a3c7c580c4ccb5c06f2ada933ad507) C:\windows\system32\DRIVERS\mrxsmb10.sys 2011/06/18 18:52:38.0390 5892 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\windows\system32\DRIVERS\mrxsmb20.sys 2011/06/18 18:52:38.0440 5892 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\windows\system32\drivers\msahci.sys 2011/06/18 18:52:38.0480 5892 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\windows\system32\drivers\msdsm.sys 2011/06/18 18:52:38.0540 5892 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\windows\system32\drivers\Msfs.sys 2011/06/18 18:52:38.0620 5892 msisadrv (0f400e306f385c56317357d6dea56f62) C:\windows\system32\drivers\msisadrv.sys 2011/06/18 18:52:38.0680 5892 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\windows\system32\drivers\MSKSSRV.sys 2011/06/18 18:52:38.0730 5892 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\windows\system32\drivers\MSPCLOCK.sys 2011/06/18 18:52:38.0790 5892 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\windows\system32\drivers\MSPQM.sys 2011/06/18 18:52:38.0850 5892 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\windows\system32\drivers\MsRPC.sys 2011/06/18 18:52:38.0900 5892 mssmbios (e384487cb84be41d09711c30ca79646c) C:\windows\system32\DRIVERS\mssmbios.sys 2011/06/18 18:52:38.0960 5892 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\windows\system32\drivers\MSTEE.sys 2011/06/18 18:52:38.0990 5892 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\windows\system32\Drivers\mup.sys 2011/06/18 18:52:39.0040 5892 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\windows\system32\DRIVERS\nwifi.sys 2011/06/18 18:52:39.0100 5892 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\windows\system32\drivers\ndis.sys 2011/06/18 18:52:39.0380 5892 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\windows\system32\DRIVERS\ndistapi.sys 2011/06/18 18:52:39.0410 5892 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\windows\system32\DRIVERS\ndisuio.sys 2011/06/18 18:52:39.0490 5892 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\windows\system32\DRIVERS\ndiswan.sys 2011/06/18 18:52:39.0540 5892 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\windows\system32\drivers\NDProxy.sys 2011/06/18 18:52:39.0640 5892 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\windows\system32\DRIVERS\netbios.sys 2011/06/18 18:52:39.0680 5892 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\windows\system32\DRIVERS\netbt.sys 2011/06/18 18:52:39.0900 5892 NETw5v32 (83f310bf50985f2a52121f2614787c38) C:\windows\system32\DRIVERS\NETw5v32.sys 2011/06/18 18:52:40.0100 5892 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\windows\system32\drivers\nfrd960.sys 2011/06/18 18:52:40.0170 5892 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\windows\system32\drivers\Npfs.sys 2011/06/18 18:52:40.0210 5892 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\windows\system32\drivers\nsiproxy.sys 2011/06/18 18:52:40.0300 5892 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\windows\system32\drivers\Ntfs.sys 2011/06/18 18:52:40.0340 5892 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\windows\system32\drivers\ntrigdigi.sys 2011/06/18 18:52:40.0370 5892 Null (c5dbbcda07d780bda9b685df333bb41e) C:\windows\system32\drivers\Null.sys 2011/06/18 18:52:40.0400 5892 nvraid (2edf9e7751554b42cbb60116de727101) C:\windows\system32\drivers\nvraid.sys 2011/06/18 18:52:40.0420 5892 nvstor (abed0c09758d1d97db0042dbb2688177) C:\windows\system32\drivers\nvstor.sys 2011/06/18 18:52:40.0480 5892 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\windows\system32\drivers\nv_agp.sys 2011/06/18 18:52:40.0580 5892 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\windows\system32\drivers\ohci1394.sys 2011/06/18 18:52:40.0660 5892 OlyCamComm (f4cb9c1991314b1352ddbd8a968e4471) C:\windows\system32\DRIVERS\OlyCamComm.sys 2011/06/18 18:52:40.0730 5892 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\windows\system32\drivers\parport.sys 2011/06/18 18:52:40.0780 5892 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\windows\system32\drivers\partmgr.sys 2011/06/18 18:52:40.0800 5892 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\windows\system32\drivers\parvdm.sys 2011/06/18 18:52:40.0900 5892 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\windows\system32\DRIVERS\pccsmcfd.sys 2011/06/18 18:52:40.0920 5892 pci (941dc1d19e7e8620f40bbc206981efdb) C:\windows\system32\drivers\pci.sys 2011/06/18 18:52:40.0950 5892 pciide (fc175f5ddab666d7f4d17449a547626f) C:\windows\system32\drivers\pciide.sys 2011/06/18 18:52:41.0010 5892 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\windows\system32\DRIVERS\pcmcia.sys 2011/06/18 18:52:41.0100 5892 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\windows\system32\drivers\peauth.sys 2011/06/18 18:52:41.0210 5892 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\windows\system32\DRIVERS\raspptp.sys 2011/06/18 18:52:41.0230 5892 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\windows\system32\drivers\processr.sys 2011/06/18 18:52:41.0290 5892 PSched (99514faa8df93d34b5589187db3aa0ba) C:\windows\system32\DRIVERS\pacer.sys 2011/06/18 18:52:41.0370 5892 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\windows\system32\Drivers\PxHelp20.sys 2011/06/18 18:52:41.0460 5892 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\windows\system32\drivers\ql2300.sys 2011/06/18 18:52:41.0560 5892 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\windows\system32\drivers\ql40xx.sys 2011/06/18 18:52:41.0600 5892 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\windows\system32\drivers\qwavedrv.sys 2011/06/18 18:52:41.0630 5892 RasAcd (147d7f9c556d259924351feb0de606c3) C:\windows\system32\DRIVERS\rasacd.sys 2011/06/18 18:52:41.0660 5892 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\windows\system32\DRIVERS\rasl2tp.sys 2011/06/18 18:52:41.0710 5892 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\windows\system32\DRIVERS\raspppoe.sys 2011/06/18 18:52:41.0740 5892 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\windows\system32\DRIVERS\rassstp.sys 2011/06/18 18:52:41.0790 5892 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\windows\system32\DRIVERS\rdbss.sys 2011/06/18 18:52:41.0810 5892 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\windows\system32\DRIVERS\RDPCDD.sys 2011/06/18 18:52:41.0870 5892 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\windows\system32\drivers\rdpdr.sys 2011/06/18 18:52:41.0880 5892 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\windows\system32\drivers\rdpencdd.sys 2011/06/18 18:52:41.0960 5892 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\windows\system32\drivers\RDPWD.sys 2011/06/18 18:52:42.0040 5892 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\windows\system32\DRIVERS\rfcomm.sys 2011/06/18 18:52:42.0120 5892 RMCAST (eec7ee5675294b03e88aa868540007c1) C:\windows\system32\DRIVERS\RMCAST.sys 2011/06/18 18:52:42.0170 5892 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\windows\system32\DRIVERS\rspndr.sys 2011/06/18 18:52:42.0210 5892 RsvLock (085ced4621302b27d86358ad6239dabe) C:\windows\system32\drivers\RsvLock.sys 2011/06/18 18:52:42.0290 5892 SafeBoot (26af84a03e2c2c5ad7abfecefc43bc4d) C:\windows\system32\drivers\SafeBoot.sys 2011/06/18 18:52:42.0290 5892 Suspicious file (NoAccess): C:\windows\system32\drivers\SafeBoot.sys. md5: 26af84a03e2c2c5ad7abfecefc43bc4d 2011/06/18 18:52:42.0300 5892 SafeBoot - detected LockedFile.Multi.Generic (1) 2011/06/18 18:52:42.0420 5892 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/06/18 18:52:42.0430 5892 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/06/18 18:52:42.0530 5892 SbAlg (587674b8cbb440691692335f7ed28e02) C:\windows\system32\drivers\SbAlg.sys 2011/06/18 18:52:42.0580 5892 SbFsLock (41c08f2da137340855bb2e4fde8fd765) C:\windows\system32\drivers\SbFsLock.sys 2011/06/18 18:52:42.0650 5892 sbp2port (3ce8f073a557e172b330109436984e30) C:\windows\system32\drivers\sbp2port.sys 2011/06/18 18:52:42.0740 5892 SCDEmu (a73ae2510014103a44a5a58845219dcb) C:\windows\system32\drivers\SCDEmu.sys 2011/06/18 18:52:42.0800 5892 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys 2011/06/18 18:52:42.0880 5892 Sentinel (8627c992b8a80504fc477b2e8ff8ec4f) C:\windows\System32\Drivers\SENTINEL.SYS 2011/06/18 18:52:42.0960 5892 Ser2pl (e42f03d1081c4f60d3db6c38235b1456) C:\windows\system32\DRIVERS\ser2pl.sys 2011/06/18 18:52:42.0990 5892 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\windows\system32\DRIVERS\serenum.sys 2011/06/18 18:52:43.0020 5892 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\windows\system32\drivers\serial.sys 2011/06/18 18:52:43.0050 5892 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\windows\system32\drivers\sermouse.sys 2011/06/18 18:52:43.0140 5892 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\windows\system32\drivers\sffdisk.sys 2011/06/18 18:52:43.0160 5892 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\windows\system32\drivers\sffp_mmc.sys 2011/06/18 18:52:43.0190 5892 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\windows\system32\drivers\sffp_sd.sys 2011/06/18 18:52:43.0200 5892 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\windows\system32\drivers\sfloppy.sys 2011/06/18 18:52:43.0240 5892 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\windows\system32\drivers\sisagp.sys 2011/06/18 18:52:43.0260 5892 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\windows\system32\drivers\sisraid2.sys 2011/06/18 18:52:43.0290 5892 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\windows\system32\drivers\sisraid4.sys 2011/06/18 18:52:43.0350 5892 Smb (7b75299a4d201d6a6533603d6914ab04) C:\windows\system32\DRIVERS\smb.sys 2011/06/18 18:52:43.0480 5892 SNP2UVC (806210bf25bba573e9331feae7ebc905) C:\windows\system32\DRIVERS\snp2uvc.sys 2011/06/18 18:52:43.0600 5892 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\windows\system32\drivers\spldr.sys 2011/06/18 18:52:43.0660 5892 sptd (71e276f6d189413266ea22171806597b) C:\windows\system32\Drivers\sptd.sys 2011/06/18 18:52:43.0660 5892 Suspicious file (NoAccess): C:\windows\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b 2011/06/18 18:52:43.0670 5892 sptd - detected LockedFile.Multi.Generic (1) 2011/06/18 18:52:43.0740 5892 srv (41987f9fc0e61adf54f581e15029ad91) C:\windows\system32\DRIVERS\srv.sys 2011/06/18 18:52:43.0810 5892 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\windows\system32\DRIVERS\srv2.sys 2011/06/18 18:52:43.0870 5892 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\windows\system32\DRIVERS\srvnet.sys 2011/06/18 18:52:43.0960 5892 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\windows\system32\DRIVERS\swenum.sys 2011/06/18 18:52:43.0990 5892 Symc8xx (192aa3ac01df071b541094f251deed10) C:\windows\system32\drivers\symc8xx.sys 2011/06/18 18:52:44.0030 5892 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\windows\system32\drivers\sym_hi.sys 2011/06/18 18:52:44.0040 5892 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\windows\system32\drivers\sym_u3.sys 2011/06/18 18:52:44.0150 5892 SynTP (5c3e900f41426a372de60675afc8aa07) C:\windows\system32\DRIVERS\SynTP.sys 2011/06/18 18:52:44.0220 5892 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\windows\system32\drivers\tcpip.sys 2011/06/18 18:52:44.0270 5892 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\windows\system32\DRIVERS\tcpip.sys 2011/06/18 18:52:44.0310 5892 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\windows\system32\drivers\tcpipreg.sys 2011/06/18 18:52:44.0350 5892 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\windows\system32\drivers\tdpipe.sys 2011/06/18 18:52:44.0380 5892 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\windows\system32\drivers\tdtcp.sys 2011/06/18 18:52:44.0440 5892 tdx (76b06eb8a01fc8624d699e7045303e54) C:\windows\system32\DRIVERS\tdx.sys 2011/06/18 18:52:44.0470 5892 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\windows\system32\DRIVERS\termdd.sys 2011/06/18 18:52:44.0530 5892 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\windows\system32\DRIVERS\tssecsrv.sys 2011/06/18 18:52:44.0600 5892 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\windows\system32\DRIVERS\tunmp.sys 2011/06/18 18:52:44.0670 5892 tunnel (300db877ac094feab0be7688c3454a9c) C:\windows\system32\DRIVERS\tunnel.sys 2011/06/18 18:52:44.0710 5892 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\windows\system32\drivers\uagp35.sys 2011/06/18 18:52:44.0760 5892 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\windows\system32\DRIVERS\udfs.sys 2011/06/18 18:52:44.0810 5892 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\windows\system32\drivers\uliagpkx.sys 2011/06/18 18:52:44.0850 5892 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\windows\system32\drivers\uliahci.sys 2011/06/18 18:52:44.0900 5892 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\windows\system32\drivers\ulsata.sys 2011/06/18 18:52:44.0960 5892 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\windows\system32\drivers\ulsata2.sys 2011/06/18 18:52:44.0980 5892 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\windows\system32\DRIVERS\umbus.sys 2011/06/18 18:52:45.0030 5892 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\windows\system32\DRIVERS\usbccgp.sys 2011/06/18 18:52:45.0050 5892 usbcir (e9476e6c486e76bc4898074768fb7131) C:\windows\system32\drivers\usbcir.sys 2011/06/18 18:52:45.0130 5892 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\windows\system32\DRIVERS\usbehci.sys 2011/06/18 18:52:45.0180 5892 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\windows\system32\DRIVERS\usbhub.sys 2011/06/18 18:52:45.0210 5892 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\windows\system32\DRIVERS\usbohci.sys 2011/06/18 18:52:45.0240 5892 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\windows\system32\DRIVERS\usbprint.sys 2011/06/18 18:52:45.0290 5892 usbscan (a508c9bd8724980512136b039bba65e9) C:\windows\system32\DRIVERS\usbscan.sys 2011/06/18 18:52:45.0330 5892 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\windows\system32\DRIVERS\USBSTOR.SYS 2011/06/18 18:52:45.0360 5892 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\windows\system32\DRIVERS\usbuhci.sys 2011/06/18 18:52:45.0400 5892 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\windows\system32\Drivers\usbvideo.sys 2011/06/18 18:52:45.0490 5892 vga (87b06e1f30b749a114f74622d013f8d4) C:\windows\system32\DRIVERS\vgapnp.sys 2011/06/18 18:52:45.0580 5892 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\windows\System32\drivers\vga.sys 2011/06/18 18:52:45.0640 5892 viaagp (5d7159def58a800d5781ba3a879627bc) C:\windows\system32\drivers\viaagp.sys 2011/06/18 18:52:45.0670 5892 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\windows\system32\drivers\viac7.sys 2011/06/18 18:52:45.0730 5892 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\windows\system32\drivers\viaide.sys 2011/06/18 18:52:45.0770 5892 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\windows\system32\drivers\volmgr.sys 2011/06/18 18:52:45.0860 5892 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\windows\system32\drivers\volmgrx.sys 2011/06/18 18:52:45.0910 5892 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\windows\system32\drivers\volsnap.sys 2011/06/18 18:52:45.0980 5892 vsmraid (587253e09325e6bf226b299774b728a9) C:\windows\system32\drivers\vsmraid.sys 2011/06/18 18:52:46.0030 5892 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\windows\system32\drivers\wacompen.sys 2011/06/18 18:52:46.0060 5892 Wanarp (55201897378cca7af8b5efd874374a26) C:\windows\system32\DRIVERS\wanarp.sys 2011/06/18 18:52:46.0090 5892 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\windows\system32\DRIVERS\wanarp.sys 2011/06/18 18:52:46.0140 5892 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\windows\system32\drivers\wd.sys 2011/06/18 18:52:46.0190 5892 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\windows\system32\drivers\Wdf01000.sys 2011/06/18 18:52:46.0290 5892 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\windows\system32\DRIVERS\wmiacpi.sys 2011/06/18 18:52:46.0380 5892 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\windows\system32\DRIVERS\wpdusb.sys 2011/06/18 18:52:46.0410 5892 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\windows\system32\drivers\ws2ifsl.sys 2011/06/18 18:52:46.0500 5892 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\windows\system32\DRIVERS\WUDFRd.sys 2011/06/18 18:52:46.0570 5892 yukonwlh (7d4cca3659fa0780603206e3d12a993f) C:\windows\system32\DRIVERS\yk60x86.sys 2011/06/18 18:52:46.0670 5892 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 2011/06/18 18:52:46.0680 5892 ================================================================================ 2011/06/18 18:52:46.0680 5892 Scan finished 2011/06/18 18:52:46.0680 5892 ================================================================================ 2011/06/18 18:52:46.0700 4608 Detected object count: 2 2011/06/18 18:52:46.0700 4608 Actual detected object count: 2 2011/06/18 18:53:07.0350 4608 LockedFile.Multi.Generic(SafeBoot) - User select action: Skip 2011/06/18 18:53:07.0350 4608 LockedFile.Multi.Generic(sptd) - User select action: Skip

Лога от TDSSKiller е чист. Това е добре. Скрипта с OTL не е сработил.

Все пак да направим една последна проверка за остатъци преди да приключим и готово:

  • Стартирайте файла Публикувано изображение с двукратен клик на мишката.
  • Сложете отметка пред Scan All Users Публикувано изображение
  • Под менюто File Age => изберете 90 days
  • Под менюто Standard Registry => променете на ALL
  • Сложете отметки пред LOP и Purity Check
  • Под Публикувано изображение с Copy/ Paste въведете следната текстова информация:
netsvcs
msconfig
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Application Data\*.*
%USERPROFILE%\Local Settings\Application Data\*.*
%AllUsersProfile%\*.*
%AllUsersProfile%\Application Data\*.*
%USERPROFILE%\My Documents\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
/md5start
hlp.dat
winlogon.exe
wininit.exe
userinit.exe
explorer.exe
volsnap.sys
/md5stop
  • Натиснете маркираният в синьо бутон: Публикувано изображение.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt.
  • Копирайте лог файловете на USB флашката и ги пренесете до машината на която имате интернет.
  • Публикувайте съдържанието на лог файловете в следващия си коментар.
  • Автор

Сканирах с OTL, но ми излезе само OTL.txt, няма extras

Ето резултата:

OTL logfile created on: 19.6.2011 г. 20:25:08 - Run 2

OTL by OldTimer - Version 3.2.24.0 Folder = C:\Users\Elitsa Danailova\Desktop

Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.19088)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: d.M.yyyy 'г.'

2,99 Gb Total Physical Memory | 1,46 Gb Available Physical Memory | 48,72% Memory free

6,18 Gb Paging File | 4,41 Gb Available in Paging File | 71,27% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files

Drive C: | 454,76 Gb Total Space | 219,56 Gb Free Space | 48,28% Space Free | Partition Type: NTFS

Drive D: | 10,00 Gb Total Space | 1,35 Gb Free Space | 13,48% Space Free | Partition Type: NTFS

Drive F: | 1022,00 Mb Total Space | 997,02 Mb Free Space | 97,56% Space Free | Partition Type: FAT32

Computer Name: ELI4KA-PC | User Name: Elitsa Danailova | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - [2011.06.16 10:58:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Elitsa Danailova\Desktop\OTL.exe

PRC - [2011.05.23 18:00:06 | 002,424,192 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

PRC - [2011.05.10 15:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe

PRC - [2011.05.10 15:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

PRC - [2011.03.07 15:49:14 | 000,234,656 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10n_ActiveX.exe

PRC - [2010.02.04 23:47:34 | 000,093,376 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program Files\Olympus\ib\olycamdetect.exe

PRC - [2009.11.07 20:18:54 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Users\Elitsa Danailova\Program Files\DNA\btdna.exe

PRC - [2009.04.11 09:28:15 | 000,117,248 | ---- | M] () -- \\?\C:\windows\System32\wbem\WMIADAP.EXE

PRC - [2009.04.11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe

PRC - [2009.03.12 17:36:24 | 000,086,016 | ---- | M] () -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe

PRC - [2009.03.01 23:21:32 | 002,329,128 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe

PRC - [2009.03.01 23:21:32 | 000,789,032 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

PRC - [2009.03.01 23:21:32 | 000,567,848 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

PRC - [2009.02.17 22:10:02 | 000,637,232 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\BitTorrent\bittorrent.exe

PRC - [2009.02.17 19:13:14 | 000,079,416 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe

PRC - [2009.02.12 09:13:34 | 000,355,896 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe

PRC - [2009.01.28 07:21:48 | 000,075,024 | ---- | M] (Bioscrypt Inc.) -- c:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe

PRC - [2009.01.15 00:01:48 | 000,077,824 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe

PRC - [2009.01.15 00:01:12 | 011,223,040 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe

PRC - [2008.12.16 19:37:46 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe

PRC - [2008.12.16 19:37:36 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

PRC - [2008.10.03 23:33:12 | 001,185,016 | ---- | M] (AuthenTec, Inc.) -- c:\Program Files\Fingerprint Sensor\AtService.exe

PRC - [2008.10.02 01:01:14 | 000,256,544 | ---- | M] (SafeBoot International) -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe

PRC - [2008.08.08 17:47:02 | 000,777,240 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe

PRC - [2008.08.08 15:11:12 | 000,490,952 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe

PRC - [2008.07.15 15:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE

PRC - [2008.04.22 17:37:56 | 001,572,864 | R--- | M] () -- C:\Program Files\UGS\UGSLicensing\ugslmd.exe

PRC - [2008.04.22 17:37:30 | 001,372,160 | R--- | M] (Macrovision Corporation) -- C:\Program Files\UGS\UGSLicensing\lmgrd.exe

PRC - [2008.01.21 05:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe

PRC - [2008.01.20 10:05:37 | 000,217,088 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE

PRC - [2007.11.28 03:42:14 | 000,185,896 | ---- | M] (ActivIdentity) -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe

PRC - [2007.11.28 03:42:12 | 000,093,736 | ---- | M] (ActivIdentity) -- c:\Program Files\ActivIdentity\ActivClient\acevents.exe

PRC - [2007.11.28 03:40:42 | 000,298,536 | ---- | M] (ActivIdentity) -- C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe

PRC - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

PRC - [2007.01.11 15:26:56 | 000,063,112 | ---- | M] (CANON INC.) -- C:\Windows\System32\CNAB4RPK.EXE

PRC - [2005.08.11 16:30:30 | 000,618,496 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

========== Modules (SafeList) ==========

MOD - [2011.06.16 10:58:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Elitsa Danailova\Desktop\OTL.exe

MOD - [2011.05.10 15:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll

MOD - [2010.08.31 18:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll

MOD - [2009.01.28 07:15:04 | 000,076,560 | ---- | M] (Bioscrypt Inc.) -- C:\Windows\System32\APSHook.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (C789634C)

SRV - [2011.05.10 15:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV - [2009.10.27 10:26:36 | 000,657,408 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

SRV - [2009.09.26 20:36:17 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)

SRV - [2009.03.12 17:36:24 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe -- (mi-raysat_3dsmax2010_32)

SRV - [2009.03.01 23:21:32 | 000,567,848 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)

SRV - [2009.02.12 09:01:06 | 000,045,056 | ---- | M] (Hewlett-Packard Development Company, L.P) [On_Demand | Stopped] -- c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe -- (HP ProtectTools Service)

SRV - [2009.01.28 07:15:16 | 000,186,640 | ---- | M] (Bioscrypt Inc.) [Auto | Running] -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll -- (ASBroker)

SRV - [2009.01.28 07:15:10 | 000,149,776 | ---- | M] (Bioscrypt Inc.) [Auto | Running] -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll -- (ASChannel)

SRV - [2009.01.15 00:01:48 | 000,077,824 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe -- (HPFSService)

SRV - [2008.12.16 19:37:46 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®

SRV - [2008.10.03 23:33:12 | 001,185,016 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- c:\Program Files\Fingerprint Sensor\AtService.exe -- (ATService)

SRV - [2008.10.02 01:01:14 | 000,256,544 | ---- | M] (SafeBoot International) [Auto | Running] -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe -- (HpFkCryptService)

SRV - [2008.08.08 17:47:02 | 000,777,240 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)

SRV - [2008.08.07 01:24:40 | 000,349,432 | ---- | M] (Hewlett-Packard Ltd) [On_Demand | Stopped] -- C:\Windows\System32\flcdlock.exe -- (FLCDLOCK)

SRV - [2008.07.15 15:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)

SRV - [2008.04.22 17:37:30 | 001,372,160 | R--- | M] (Macrovision Corporation) [Auto | Running] -- C:\Program Files\UGS\UGSLicensing\lmgrd.exe -- (UGS License Server (ugslmd)) UGS License Server (ugslmd)

SRV - [2008.04.08 14:12:50 | 001,112,560 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)

SRV - [2008.01.21 05:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV - [2007.11.28 03:42:14 | 000,185,896 | ---- | M] (ActivIdentity) [Auto | Running] -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe -- (accoca)

SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)

========== Driver Services (SafeList) ==========

DRV - [2011.05.10 15:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\windows\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2011.05.10 15:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2011.05.10 15:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2011.05.10 14:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2011.05.10 14:59:44 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)

DRV - [2011.05.10 14:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2010.05.10 21:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)

DRV - [2010.02.17 21:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)

DRV - [2009.09.26 17:09:23 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\System32\Drivers\sptd.sys -- (sptd)

DRV - [2009.09.10 16:58:26 | 000,021,648 | ---- | M] (OLYMPUS IMAGING CORP.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\OlyCamComm.sys -- (OlyCamComm)

DRV - [2009.04.11 07:45:24 | 000,113,664 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST) RMCAST (Pgm)

DRV - [2009.03.31 12:26:00 | 004,232,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel®

DRV - [2009.03.26 14:39:14 | 001,765,168 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)

DRV - [2009.03.23 09:02:15 | 000,043,136 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ser2pl.sys -- (Ser2pl)

DRV - [2009.02.19 14:17:00 | 000,095,760 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)

DRV - [2009.02.03 16:29:00 | 004,303,360 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)

DRV - [2008.10.29 18:43:44 | 001,204,128 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2008.10.02 01:02:04 | 000,051,408 | ---- | M] (SafeBoot N.V.) [Kernel | Boot | Running] -- C:\windows\System32\drivers\SbAlg.sys -- (SbAlg)

DRV - [2008.10.02 01:02:02 | 000,012,960 | ---- | M] (SafeBoot International) [File_System | Boot | Running] -- C:\windows\System32\drivers\SbFsLock.sys -- (SbFsLock)

DRV - [2008.10.02 01:02:00 | 000,012,528 | ---- | M] (SafeBoot International) [Kernel | System | Running] -- C:\windows\System32\drivers\rsvlock.sys -- (RsvLock)

DRV - [2008.10.02 01:01:58 | 000,109,216 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\System32\drivers\SafeBoot.sys -- (SafeBoot)

DRV - [2008.08.27 19:52:02 | 000,034,608 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)

DRV - [2008.08.27 19:52:02 | 000,025,392 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)

DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)

DRV - [2008.08.07 00:43:30 | 000,032,256 | ---- | M] (Hewlett-Packard Development Company L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DAMDrv.sys -- (DAMDrv)

DRV - [2008.01.20 10:07:58 | 000,033,292 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\windows\System32\drivers\scdemu.sys -- (SCDEmu)

DRV - [2007.06.19 02:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)

DRV - [2006.06.12 13:36:30 | 000,009,344 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hpfxbulk.sys -- (HPFXBULK)

DRV - [2004.11.05 12:08:06 | 000,670,208 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (Hardlock)

DRV - [2001.06.22 06:39:02 | 000,073,728 | ---- | M] (Rainbow Technologies, Inc.) [Kernel | Auto | Running] -- C:\windows\System32\Drivers\SENTINEL.SYS -- (Sentinel)

========== Standard Registry (All) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_bg&c=92&bd=all&pf=cmnb

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/

IE - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=966134"

FF - prefs.js..browser.search.selectedEngine: "Yahoo"

FF - prefs.js..browser.startup.homepage: "www.google.bg"

FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1

FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3

FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=966134&p="

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.09.26 19:45:52 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.29 17:41:14 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.18 21:25:51 | 000,000,000 | ---D | M]

[2009.09.26 17:01:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Elitsa Danailova\AppData\Roaming\Mozilla\Extensions

[2009.09.26 17:01:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Elitsa Danailova\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2010.08.31 17:45:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Elitsa Danailova\AppData\Roaming\Mozilla\Firefox\Profiles\uery3fak.default\extensions

[2009.09.26 20:20:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Elitsa Danailova\AppData\Roaming\Mozilla\Firefox\Profiles\uery3fak.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011.06.18 18:09:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2009.10.11 19:11:26 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2011.03.03 17:51:20 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

[2009.10.11 19:11:27 | 000,000,000 | ---D | M] (Talkback) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]

File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

[2011.06.19 20:19:35 | 000,000,000 | ---D | M] (No name found) -- C:\USERS\ELITSA DANAILOVA\PROGRAM FILES\DNA

[2009.09.26 20:21:08 | 000,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll

[2009.09.26 20:21:08 | 000,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll

[2008.04.07 10:16:09 | 000,067,696 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jar50.dll

[2008.04.07 10:16:09 | 000,054,376 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jsd3250.dll

[2008.04.07 10:16:09 | 000,034,952 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\myspell.dll

[2008.04.07 10:16:09 | 000,046,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\spellchk.dll

[2008.04.07 10:16:09 | 000,172,144 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\xpinstal.dll

[2008.09.04 03:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll

[2007.02.05 00:02:56 | 001,642,496 | ---- | M] (LizardTech) -- C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll

[2008.04.07 10:16:10 | 000,022,664 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll

[2007.01.18 01:05:32 | 000,002,368 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml

[2006.09.14 08:32:05 | 000,001,040 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-bg.xml

[2011.03.21 18:46:28 | 000,000,846 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2011.06.17 12:14:34 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (BHO_Startup Class) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)

O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [accrdsub] c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)

O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)

O4 - HKLM..\Run: [CognizanceTS] c:\Program Files\Hewlett-Packard\IAM\Bin\ASTSVCC.dll (Bioscrypt Inc.)

O4 - HKLM..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe (Hewlett-Packard)

O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)

O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files\Hewlett-Packard\HP Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [MDS_Menu] C:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)

O4 - HKLM..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)

O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)

O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)

O4 - HKLM..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)

O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKLM..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard)

O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\windows\System32\oobefldr.dll (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\windows\System32\oobefldr.dll (Microsoft Corporation)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [bitTorrent] C:\Program Files\BitTorrent\bittorrent.exe (BitTorrent, Inc.)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [bitTorrent DNA] C:\Users\Elitsa Danailova\Program Files\DNA\btdna.exe (BitTorrent, Inc.)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [ehTray.exe] C:\Windows\ehome\ehtray.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [iSUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [Olympus ib] C:\Program Files\Olympus\ib\olycamdetect.exe (OLYMPUS IMAGING CORP.)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

O4 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17

O7 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153

O8 - Extra context menu item: E&xport to Microsoft Excel - c:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()

O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)

O13 - gopher Prefix: missing

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.9.239.90 217.9.239.94

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - AppInit_DLLs: (APSHook.dll) - C:\windows\System32\APSHook.dll (Bioscrypt Inc.)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\windows\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\windows\System32\sysdm.cpl (Microsoft Corporation)

O20 - HKU\S-1-5-21-188209174-3304326258-1817674253-1004 Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\DeviceNP: DllName - DeviceNP.dll - C:\windows\System32\DeviceNP.dll (Hewlett-Packard Limited)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\System32\browseui.dll (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Users\Elitsa Danailova\Pictures\dogs\New Folder\2f37a4e650e663d464b736c1d3b35d30.jpg

O24 - Desktop BackupWallPaper: C:\Users\Elitsa Danailova\Pictures\dogs\New Folder\2f37a4e650e663d464b736c1d3b35d30.jpg

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (credssp.dll) - C:\windows\System32\credssp.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\windows\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) - C:\windows\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\windows\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\windows\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\windows\System32\wdigest.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (tspkg) - C:\windows\System32\tspkg.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found

NetSvcs: Ias - File not found

NetSvcs: Nla - File not found

NetSvcs: Ntmssvc - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: SRService - File not found

NetSvcs: WmdmPmSp - File not found

NetSvcs: LogonHours - File not found

NetSvcs: PCAudit - File not found

NetSvcs: helpsvc - File not found

NetSvcs: uploadmgr - File not found

========== Files/Folders - Created Within 90 Days ==========

[2011.06.18 18:50:54 | 001,441,584 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Elitsa Danailova\Desktop\TDSSKiller.exe

[2011.06.17 15:40:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2011.06.17 15:40:17 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Elitsa Danailova\Desktop\esetsmartinstaller_enu.exe

[2011.06.17 15:13:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rootkit Unhooker LE

[2011.06.17 15:13:42 | 000,000,000 | ---D | C] -- C:\windows\System32\MustBeRandomlyNamed

[2011.06.17 15:12:40 | 000,719,574 | ---- | C] (UG North ) -- C:\Users\Elitsa Danailova\Desktop\RkU3.8.388.590.exe

[2011.06.17 14:20:08 | 000,581,120 | ---- | C] (AVAST Software) -- C:\Users\Elitsa Danailova\Desktop\aswMBR.exe

[2011.06.17 14:15:02 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll

[2011.06.17 14:14:56 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll

[2011.06.17 14:14:53 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\inetcpl.cpl

[2011.06.17 14:14:53 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mstime.dll

[2011.06.17 14:14:53 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll

[2011.06.17 14:14:53 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\html.iec

[2011.06.17 14:14:53 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll

[2011.06.17 14:14:53 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieui.dll

[2011.06.17 14:14:53 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieUnatt.exe

[2011.06.17 14:14:52 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iesysprep.dll

[2011.06.17 14:14:52 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iesetup.dll

[2011.06.17 14:14:52 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iernonce.dll

[2011.06.17 14:14:52 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll

[2011.06.17 14:14:52 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll

[2011.06.17 14:14:50 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb

[2011.06.17 14:14:50 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ie4uinit.exe

[2011.06.17 14:14:50 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe

[2011.06.17 12:14:11 | 000,000,000 | ---D | C] -- C:\_OTL

[2011.06.16 10:59:00 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Elitsa Danailova\Desktop\OTL.exe

[2011.06.09 17:34:13 | 000,000,000 | ---D | C] -- C:\Users\Elitsa Danailova\AppData\Roaming\SUPERAntiSpyware.com

[2011.06.09 17:34:13 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com

[2011.06.09 17:33:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware

[2011.06.09 17:33:54 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware

[2011.06.09 14:49:29 | 000,000,000 | ---D | C] -- C:\Users\Elitsa Danailova\AppData\Roaming\Malwarebytes

[2011.06.09 14:49:23 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2011.06.09 14:49:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011.06.09 14:49:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2011.06.09 14:49:20 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2011.06.09 14:49:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011.05.15 16:27:37 | 000,000,000 | ---D | C] -- C:\Users\Elitsa Danailova\Desktop\depron

[2011.05.15 16:10:37 | 000,000,000 | ---D | C] -- C:\Users\Elitsa Danailova\Documents\SW Log Files

[2011.05.01 16:14:24 | 004,240,384 | ---- | C] (Microsoft) -- C:\windows\System32\GameUXLegacyGDFs.dll

[2011.05.01 16:14:24 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\Apphlpdm.dll

[2011.05.01 16:14:16 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XpsPrint.dll

[2011.04.16 19:24:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Audio Converter

[2011.04.16 19:24:54 | 000,000,000 | ---D | C] -- C:\Program Files\Magic Audio Converter

[2011.04.15 12:37:42 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\System32\atmfd.dll

[2011.04.15 12:37:42 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\windows\System32\atmlib.dll

[2011.04.15 12:37:27 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mfc42u.dll

[2011.04.15 12:37:27 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mfc42.dll

[2011.04.15 12:37:25 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\dnscacheugc.exe

[2011.04.15 12:37:24 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys

[2011.04.15 12:37:22 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jscript.dll

[2011.04.15 12:37:21 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\vbscript.dll

[2011.03.26 12:33:30 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee

[2011.03.22 20:25:12 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\DWrite.dll

[2011.03.22 20:25:12 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XpsGdiConverter.dll

[2009.09.10 10:05:48 | 000,256,560 | ---- | C] ( ) -- C:\windows\System32\rsnp2uvc.dll

[2009.09.10 10:05:46 | 000,203,312 | ---- | C] ( ) -- C:\windows\System32\csnp2uvc.dll

========== Files - Modified Within 90 Days ==========

[2011.06.19 20:25:30 | 000,634,400 | ---- | M] () -- C:\windows\System32\perfh009.dat

[2011.06.19 20:25:30 | 000,119,964 | ---- | M] () -- C:\windows\System32\perfc009.dat

[2011.06.19 20:24:48 | 000,000,440 | -H-- | M] () -- C:\windows\tasks\User_Feed_Synchronization-{0236E6BD-F06D-454B-8F4A-5A25B47BE46E}.job

[2011.06.19 20:19:23 | 000,065,536 | ---- | M] () -- C:\windows\System32\Ikeext.etl

[2011.06.19 20:19:21 | 000,001,002 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job

[2011.06.19 20:19:18 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2011.06.19 20:19:17 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2011.06.19 20:19:09 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat

[2011.06.19 20:19:05 | 3215,212,544 | -HS- | M] () -- C:\hiberfil.sys

[2011.06.18 20:16:19 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat

[2011.06.18 20:16:00 | 000,001,006 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job

[2011.06.18 19:51:45 | 000,020,992 | ---- | M] () -- C:\Users\Elitsa Danailova\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.06.18 18:50:51 | 001,309,375 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\tdsskiller.zip

[2011.06.17 15:40:17 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Elitsa Danailova\Desktop\esetsmartinstaller_enu.exe

[2011.06.17 14:20:13 | 000,581,120 | ---- | M] (AVAST Software) -- C:\Users\Elitsa Danailova\Desktop\aswMBR.exe

[2011.06.17 12:14:34 | 000,000,098 | ---- | M] () -- C:\windows\System32\drivers\etc\Hosts

[2011.06.16 15:28:52 | 001,441,584 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Elitsa Danailova\Desktop\TDSSKiller.exe

[2011.06.16 11:17:06 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk

[2011.06.16 10:58:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Elitsa Danailova\Desktop\OTL.exe

[2011.06.12 17:30:07 | 000,005,642 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys

[2011.06.09 17:33:57 | 000,001,800 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk

[2011.06.09 14:49:23 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2011.06.07 19:29:52 | 000,002,255 | ---- | M] () -- C:\Users\Elitsa Danailova\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2011.06.05 20:52:18 | 000,002,703 | ---- | M] () -- C:\Users\Elitsa Danailova\Application Data\Microsoft\Internet Explorer\Quick Launch\CorelDRAW X4.lnk

[2011.05.29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2011.05.29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2011.05.28 09:05:27 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mstime.dll

[2011.05.28 09:04:56 | 000,602,112 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll

[2011.05.28 09:04:56 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll

[2011.05.28 09:04:30 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll

[2011.05.28 09:04:22 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll

[2011.05.28 09:04:17 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\inetcpl.cpl

[2011.05.28 09:04:03 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieui.dll

[2011.05.28 09:04:03 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iesysprep.dll

[2011.05.28 09:04:03 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iesetup.dll

[2011.05.28 09:04:02 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll

[2011.05.28 09:04:02 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iernonce.dll

[2011.05.28 09:03:58 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll

[2011.05.28 08:10:26 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\html.iec

[2011.05.28 07:33:03 | 000,133,632 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieUnatt.exe

[2011.05.28 07:32:51 | 000,173,568 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ie4uinit.exe

[2011.05.28 07:32:15 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe

[2011.05.28 07:31:44 | 001,638,912 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb

[2011.05.17 20:17:18 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt

[2011.05.15 16:12:09 | 000,002,485 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\DWGeditor.lnk

[2011.05.14 22:01:00 | 061,145,246 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\New Folder (3).rar

[2011.05.10 15:10:59 | 000,040,112 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr

[2011.05.10 15:10:55 | 000,199,304 | ---- | M] (AVAST Software) -- C:\windows\System32\aswBoot.exe

[2011.05.10 15:03:54 | 000,441,176 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswSnx.sys

[2011.05.10 15:03:44 | 000,307,928 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswSP.sys

[2011.05.10 15:02:37 | 000,049,240 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswTdi.sys

[2011.05.10 14:59:56 | 000,025,432 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswRdr.sys

[2011.05.10 14:59:44 | 000,053,592 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswMonFlt.sys

[2011.05.10 14:59:35 | 000,019,544 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswFsBlk.sys

[2011.05.03 10:11:36 | 000,030,532 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\XM 1351.pdf

[2011.05.03 10:11:10 | 000,008,304 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\M 1350.pdf

[2011.05.03 10:10:58 | 000,008,869 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\M 1352.pdf

[2011.05.03 09:46:56 | 000,438,550 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\octanorm1.bmp

[2011.04.24 13:36:54 | 002,752,538 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0376.jpg

[2011.04.24 13:36:54 | 002,707,585 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0385.jpg

[2011.04.24 13:36:54 | 002,636,673 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0380.jpg

[2011.04.24 13:36:54 | 002,607,450 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0384.jpg

[2011.04.24 13:36:53 | 002,671,715 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0383.jpg

[2011.04.24 13:36:53 | 002,634,351 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0379.jpg

[2011.04.24 13:36:53 | 002,620,251 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0386.jpg

[2011.04.16 19:24:55 | 000,000,781 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop\Magic Audio Converter.lnk

[2011.04.15 20:11:34 | 001,779,992 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT

[2011.04.02 16:41:06 | 098,965,975 | ---- | M] () -- C:\Users\Elitsa Danailova\Documents\P4020366.MP4

[2011.04.02 16:37:08 | 170,397,583 | ---- | M] () -- C:\Users\Elitsa Danailova\Documents\P4020365.MP4

[2011.04.02 14:51:54 | 018,197,211 | ---- | M] () -- C:\Users\Elitsa Danailova\Documents\P4020364.MP4

[2011.03.27 22:22:48 | 000,002,651 | ---- | M] () -- C:\Users\Elitsa Danailova\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk

========== Files Created - No Company Name ==========

[2011.06.18 18:50:38 | 001,309,375 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\tdsskiller.zip

[2011.06.09 17:33:57 | 000,001,800 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk

[2011.06.09 14:55:41 | 3215,212,544 | -HS- | C] () -- C:\hiberfil.sys

[2011.06.09 14:49:23 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2011.05.14 22:00:37 | 061,145,246 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\New Folder (3).rar

[2011.05.03 11:56:20 | 000,438,550 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\octanorm1.bmp

[2011.05.03 11:56:20 | 000,030,532 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\XM 1351.pdf

[2011.05.03 11:56:20 | 000,008,869 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\M 1352.pdf

[2011.05.03 11:56:20 | 000,008,304 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\M 1350.pdf

[2011.04.24 13:36:44 | 002,752,538 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0376.jpg

[2011.04.24 13:36:44 | 002,636,673 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0380.jpg

[2011.04.24 13:36:44 | 002,634,351 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0379.jpg

[2011.04.24 13:36:44 | 002,620,251 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0386.jpg

[2011.04.24 13:36:43 | 002,707,585 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0385.jpg

[2011.04.24 13:36:43 | 002,671,715 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0383.jpg

[2011.04.24 13:36:43 | 002,607,450 | ---- | C] () -- C:\Users\Elitsa Danailova\IMG_0384.jpg

[2011.04.16 19:24:55 | 000,000,781 | ---- | C] () -- C:\Users\Elitsa Danailova\Desktop\Magic Audio Converter.lnk

[2011.04.05 20:12:53 | 098,965,975 | ---- | C] () -- C:\Users\Elitsa Danailova\Documents\P4020366.MP4

[2011.04.05 20:12:43 | 170,397,583 | ---- | C] () -- C:\Users\Elitsa Danailova\Documents\P4020365.MP4

[2011.04.05 20:12:42 | 018,197,211 | ---- | C] () -- C:\Users\Elitsa Danailova\Documents\P4020364.MP4

[2011.02.11 20:20:39 | 000,000,680 | ---- | C] () -- C:\Users\Elitsa Danailova\AppData\Local\d3d9caps.dat

[2011.02.10 21:02:28 | 000,000,127 | ---- | C] () -- C:\windows\System32\MRT.INI

[2010.06.06 17:20:02 | 000,065,344 | ---- | C] () -- C:\windows\System32\PDFreDirectMonNT.dll

[2010.06.05 10:50:11 | 000,114,816 | ---- | C] () -- C:\windows\hpgins21.dat.temp

[2010.06.05 10:50:11 | 000,000,282 | ---- | C] () -- C:\windows\hpgmdl21.dat.temp

[2010.02.18 19:58:54 | 000,132,284 | R--- | C] () -- C:\Program Files\nx6.lic

[2010.01.04 13:00:51 | 000,000,000 | ---- | C] () -- C:\windows\eDrawingOfficeAutomator.INI

[2009.12.13 13:32:32 | 000,115,320 | ---- | C] () -- C:\windows\hpgins21.dat

[2009.10.08 19:14:51 | 000,241,664 | ---- | C] () -- C:\windows\System32\hppapr04.DLL

[2009.10.08 19:14:51 | 000,000,526 | ---- | C] () -- C:\windows\System32\hppapr04.DAT

[2009.09.26 20:31:08 | 000,117,248 | ---- | C] () -- C:\windows\System32\EhStorAuthn.dll

[2009.09.26 20:31:08 | 000,107,612 | ---- | C] () -- C:\windows\System32\StructuredQuerySchema.bin

[2009.09.26 19:37:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

[2009.09.26 16:59:55 | 000,168,448 | ---- | C] () -- C:\windows\System32\unrar.dll

[2009.09.26 16:59:55 | 000,000,038 | ---- | C] () -- C:\windows\avisplitter.ini

[2009.09.26 16:59:54 | 000,881,664 | ---- | C] () -- C:\windows\System32\xvidcore.dll

[2009.09.26 16:59:53 | 003,596,288 | ---- | C] () -- C:\windows\System32\qt-dx331.dll

[2009.09.26 16:59:53 | 000,205,824 | ---- | C] () -- C:\windows\System32\xvidvfw.dll

[2009.09.26 16:59:52 | 000,085,504 | ---- | C] () -- C:\windows\System32\ff_vfw.dll

[2009.09.10 17:41:52 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin

[2009.09.10 17:41:11 | 000,000,012 | ---- | C] () -- C:\windows\bthservsdp.dat

[2009.09.10 10:41:36 | 000,020,992 | ---- | C] () -- C:\Users\Elitsa Danailova\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.09.10 10:32:51 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys

[2009.09.10 10:32:51 | 000,000,008 | RHS- | C] () -- C:\ProgramData\E7EFFA150C.sys

[2009.09.10 10:05:47 | 001,765,168 | ---- | C] () -- C:\windows\System32\drivers\snp2uvc.sys

[2009.09.10 10:05:47 | 000,034,480 | ---- | C] () -- C:\windows\System32\drivers\sncduvc.sys

[2009.09.10 10:05:47 | 000,027,184 | ---- | C] () -- C:\windows\snuvcdsm.exe

[2009.09.10 10:05:47 | 000,015,497 | ---- | C] () -- C:\windows\snp2uvc.ini

[2009.06.24 08:33:42 | 000,018,904 | ---- | C] () -- C:\windows\System32\StructuredQuerySchemaTrivial.bin

[2009.02.03 14:00:00 | 000,159,744 | ---- | C] () -- C:\windows\System32\atitmmxx.dll

[2009.02.03 14:00:00 | 000,011,264 | ---- | C] () -- C:\windows\System32\atimuixx.dll

[2008.10.29 07:13:00 | 000,180,720 | ---- | C] () -- C:\windows\System32\atiicdxx.dat

[2008.10.21 02:40:00 | 000,081,920 | ---- | C] () -- C:\windows\System32\ATIODE.exe

[2008.10.21 02:40:00 | 000,045,056 | ---- | C] () -- C:\windows\System32\ATIODCLI.exe

[2008.10.02 01:01:58 | 000,109,216 | ---- | C] () -- C:\windows\System32\drivers\SafeBoot.sys

[2008.08.07 01:19:14 | 000,294,912 | ---- | C] () -- C:\windows\System32\flcdlmsg.dll

[2007.11.28 03:41:06 | 000,114,688 | ---- | C] () -- C:\windows\System32\aicext.dll

[2007.05.02 20:39:06 | 000,000,282 | ---- | C] () -- C:\windows\hpgmdl21.dat

[2006.11.02 15:57:28 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat

[2006.11.02 15:47:37 | 001,779,992 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT

[2006.11.02 15:35:32 | 000,005,632 | ---- | C] () -- C:\windows\System32\sysprepMCE.dll

[2006.11.02 13:33:01 | 000,634,400 | ---- | C] () -- C:\windows\System32\perfh009.dat

[2006.11.02 13:33:01 | 000,287,440 | ---- | C] () -- C:\windows\System32\perfi009.dat

[2006.11.02 13:33:01 | 000,119,964 | ---- | C] () -- C:\windows\System32\perfc009.dat

[2006.11.02 13:33:01 | 000,030,674 | ---- | C] () -- C:\windows\System32\perfd009.dat

[2006.11.02 13:23:21 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat

[2006.11.02 11:58:30 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin

[2006.11.02 11:19:00 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT

[2006.11.02 10:40:29 | 000,013,750 | ---- | C] () -- C:\windows\System32\pacerprf.ini

[2006.11.02 10:25:31 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat

[2006.06.13 17:35:32 | 000,053,760 | ---- | C] () -- C:\windows\System32\zlib.dll

[2005.04.04 02:30:00 | 000,110,592 | ---- | C] () -- C:\windows\System32\scardsyn.dll

[2003.12.09 01:08:20 | 002,539,520 | ---- | C] () -- C:\windows\System32\Bbgspdf.dll

[2003.12.02 14:39:08 | 000,094,208 | ---- | C] () -- C:\windows\System32\InstallPrinter.dll

[2003.01.30 07:04:00 | 000,618,496 | ---- | C] () -- C:\windows\System32\stlpmt45.dll

[1998.05.07 07:10:00 | 000,069,632 | ---- | C] () -- C:\windows\System32\ODMA32.dll

========== LOP Check ==========

[2009.09.26 17:32:44 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\Ashampoo

[2009.09.26 20:42:07 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\Autodesk

[2011.06.19 20:29:19 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\BitTorrent

[2011.03.06 01:23:31 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\BSplayer PRO

[2009.09.26 17:09:08 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\DAEMON Tools

[2011.06.19 20:29:39 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\DNA

[2010.01.03 14:22:19 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\DWGeditor

[2011.03.19 20:57:49 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\FriendsGamesNetwork

[2011.05.15 14:31:37 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\Image Zone Express

[2009.09.10 10:32:54 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\InterVideo

[2009.12.16 01:46:36 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\Nokia

[2009.12.15 23:01:27 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\PC Suite

[2011.02.27 20:20:57 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\PDF reDirect

[2009.12.13 14:09:36 | 000,000,000 | ---D | M] -- C:\Users\Elitsa Danailova\AppData\Roaming\Printer Info Cache

[2011.06.18 20:16:20 | 000,032,542 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

[2011.06.19 20:24:48 | 000,000,440 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{0236E6BD-F06D-454B-8F4A-5A25B47BE46E}.job

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2009.04.11 09:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr

[2011.06.19 20:19:05 | 3215,212,544 | -HS- | M] () -- C:\hiberfil.sys

[2010.12.01 20:23:12 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2010.12.01 20:23:12 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2011.06.19 20:19:02 | 3528,933,376 | -HS- | M] () -- C:\pagefile.sys

[2011.06.18 18:54:47 | 000,067,928 | ---- | M] () -- C:\TDSSKiller.2.5.5.0_18.06.2011_18.52.17_log.txt

< %USERPROFILE%\*.* >

[2010.05.06 12:32:30 | 000,004,096 | ---- | M] () -- C:\Users\Elitsa Danailova\00010004.ci

[2010.05.06 12:32:30 | 000,004,096 | ---- | M] () -- C:\Users\Elitsa Danailova\Contacts(0001)

[2010.05.06 12:32:30 | 000,004,096 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop(0001)

[2010.05.06 12:32:30 | 000,065,536 | ---- | M] () -- C:\Users\Elitsa Danailova\Desktop(0002)

[2011.04.24 13:36:54 | 002,752,538 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0376.jpg

[2011.04.24 13:36:53 | 002,634,351 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0379.jpg

[2011.04.24 13:36:54 | 002,636,673 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0380.jpg

[2011.04.24 13:36:53 | 002,671,715 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0383.jpg

[2011.04.24 13:36:54 | 002,607,450 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0384.jpg

[2011.04.24 13:36:54 | 002,707,585 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0385.jpg

[2011.04.24 13:36:53 | 002,620,251 | ---- | M] () -- C:\Users\Elitsa Danailova\IMG_0386.jpg

[2011.06.19 20:29:36 | 004,718,592 | -HS- | M] () -- C:\Users\Elitsa Danailova\ntuser.dat

[2011.06.19 20:29:36 | 000,262,144 | -H-- | M] () -- C:\Users\Elitsa Danailova\ntuser.dat.LOG1

[2009.09.10 10:00:10 | 000,000,000 | -H-- | M] () -- C:\Users\Elitsa Danailova\ntuser.dat.LOG2

[2011.03.07 17:59:15 | 000,065,536 | -HS- | M] () -- C:\Users\Elitsa Danailova\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf

[2011.03.07 17:59:15 | 000,524,288 | -HS- | M] () -- C:\Users\Elitsa Danailova\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms

[2009.09.10 10:57:50 | 000,524,288 | -HS- | M] () -- C:\Users\Elitsa Danailova\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms

[2011.06.18 20:16:18 | 000,065,536 | -HS- | M] () -- C:\Users\Elitsa Danailova\ntuser.dat{ebf7a5af-4a3b-11e0-bfa2-00247e7b9006}.TM.blf

[2011.06.18 20:16:18 | 000,524,288 | -HS- | M] () -- C:\Users\Elitsa Danailova\ntuser.dat{ebf7a5af-4a3b-11e0-bfa2-00247e7b9006}.TMContainer00000000000000000001.regtrans-ms

[2011.03.09 14:03:01 | 000,524,288 | -HS- | M] () -- C:\Users\Elitsa Danailova\ntuser.dat{ebf7a5af-4a3b-11e0-bfa2-00247e7b9006}.TMContainer00000000000000000002.regtrans-ms

[2009.09.10 10:00:10 | 000,000,020 | -HS- | M] () -- C:\Users\Elitsa Danailova\ntuser.ini

< %USERPROFILE%\Application Data\*.* >

< %USERPROFILE%\Local Settings\Application Data\*.* >

< %AllUsersProfile%\*.* >

[2009.09.10 10:32:51 | 000,000,008 | RHS- | M] () -- C:\ProgramData\E7EFFA150C.sys

[2009.09.26 19:37:31 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat

[2009.06.24 10:38:14 | 000,000,253 | ---- | M] () -- C:\ProgramData\HPWALog.txt

[2010.06.05 11:28:30 | 000,005,838 | ---- | M] () -- C:\ProgramData\hpzinstall.log

[2011.06.12 17:30:07 | 000,005,642 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys

< %AllUsersProfile%\Application Data\*.* >

< %USERPROFILE%\My Documents\*.* >

< %CommonProgramFiles%\*.* >

< %PROGRAMFILES%\*.* >

[2008.01.21 05:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

[2008.07.03 22:50:05 | 000,132,284 | R--- | M] () -- C:\Program Files\nx6.lic

[2010.02.18 20:00:15 | 000,264,570 | ---- | M] () -- C:\Program Files\nx6.txt

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >

[2011.04.21 16:58:27 | 000,273,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\afd.sys

[2011.05.10 14:59:35 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys

[2011.05.10 14:59:44 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys

[2011.05.10 14:59:56 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys

[2011.05.10 15:03:54 | 000,441,176 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys

[2011.05.10 15:03:44 | 000,307,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys

[2011.05.10 15:02:37 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys

[2011.04.14 17:59:03 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\dfsc.sys

[2011.05.29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys

[2011.05.29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys

[2011.04.29 16:24:40 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb.sys

[2011.04.29 16:24:50 | 000,214,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys

[2011.04.29 16:24:42 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb20.sys

[2011.04.29 16:25:10 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys

[2011.04.29 16:25:09 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srvnet.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

[2008.10.02 01:01:58 | 000,109,216 | ---- | M] () Unable to obtain MD5 -- C:\Windows\System32\drivers\SafeBoot.sys

[2009.09.26 17:09:23 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\Windows\System32\drivers\sptd.sys

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

[2006.04.25 06:07:24 | 000,069,120 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\hpzpp43e.dll

[2006.11.02 15:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

[2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< MD5 for: EXPLORER.EXE >

[2009.06.24 08:54:52 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe

[2009.06.24 08:54:52 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe

[2009.06.24 08:54:51 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe

[2009.04.11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe

[2009.04.11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe

[2009.06.24 08:54:52 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe

[2008.01.21 05:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: USERINIT.EXE >

[2008.01.21 05:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe

[2008.01.21 05:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe

< MD5 for: VOLSNAP.SYS >

[2006.11.02 12:51:18 | 000,208,488 | ---- | M] (Microsoft Corporation) MD5=11EF6C1CAEF76B685233450A126125D6 -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_9320b452\volsnap.sys

[2009.04.11 09:32:55 | 000,226,280 | ---- | M] (Microsoft Corporation) MD5=147281C01FCB1DF9252DE2A10D5E7093 -- C:\Windows\System32\drivers\volsnap.sys

[2009.04.11 09:32:55 | 000,226,280 | ---- | M] (Microsoft Corporation) MD5=147281C01FCB1DF9252DE2A10D5E7093 -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_1e6030e4\volsnap.sys

[2009.04.11 09:32:55 | 000,226,280 | ---- | M] (Microsoft Corporation) MD5=147281C01FCB1DF9252DE2A10D5E7093 -- C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6002.18005_none_17a2308cf936c619\volsnap.sys

[2008.01.21 05:23:21 | 000,227,896 | ---- | M] (Microsoft Corporation) MD5=D8B4A53DD2769F226B3EB374374987C9 -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_f53a1785\volsnap.sys

[2008.01.21 05:23:21 | 000,227,896 | ---- | M] (Microsoft Corporation) MD5=D8B4A53DD2769F226B3EB374374987C9 -- C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6001.18000_none_15b6b780fc14facd\volsnap.sys

< MD5 for: WININIT.EXE >

[2008.01.21 05:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe

[2008.01.21 05:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe

< MD5 for: WINLOGON.EXE >

[2009.04.11 09:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe

[2009.04.11 09:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe

[2008.01.21 05:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< End of report >

Супер...лог файла е чист. :cheers:

Финални препоръки:

1- Отворете Start => долу в търсачката напишете CMD.exe => кликнете с десен бутон върху файла и изберете => Run as administrator

Публикувано изображение

Въведете следната команда:

sc delete C789634C => натиснете Enter

Затворете конзолата (CMD.exe).

2- Вие използвате avast!5 => Препоръчвам ви да я деинсталирате и да качите последната версия avast! 6.0.1125 Final

Обновете дефинициите и направете пълна проверка на системата си (за всеки случай).

3- За да премахнете всички инструменти, коити използвахме, а също файловете и папките, които те създават, моля, направете следното:

Стартирайте OTL още веднъж и натиснете бутона CleanUp.

Публикувано изображение

Ако бъдете подканени да рестартирате, се съгласете.

Ако случайно не се изтрият следните инструменти и тяхните логове го направете ръчно:

Изтрийте: aswMBR, Rootkit UnHooker, TDSSKiller и техните логове...

Деинсталирайте: ESET Online Scanner

Поздрави !

  • Автор

Направено! Инсталирах Аваст, сканирах, не откри нищо. Май го преборихме! За което страшно много благодаря! Може ли само да попитам Аваст достатъчен ли е да ме предпази, ако на някоя от флашките ми е останала някаква гадина? Мога ли да ги сканирам с нещо и да ги почистя, защото подозирам, че чрез някоя флашка съм си лепнала тази гадост.

Вижте тази програма Panda USB Vaccine. Чрез нея може да изключите AutoRun функцията на Windows и да имунизирате флашките срещу ауторън заплахи.Самите флашки сканирайте с антивирусната програма.

Направено!

Инсталирах Аваст, сканирах, не откри нищо.

Май го преборихме! За което страшно много благодаря!

Може ли само да попитам Аваст достатъчен ли е да ме предпази, ако на някоя от флашките ми е останала някаква гадина? Мога ли да ги сканирам с нещо и да ги почистя, защото подозирам, че чрез някоя флашка съм си лепнала тази гадост.

Здравейте,

simens123 е дал доста добро решение на проблема с USB autorun заплахите (само че Panda USB Vaccine не сканира за заплахи, а само спира autorun-a - което в повечето случаи би трябвало да е достатъчно).

Можете да опитате и Flash_Disinfector (от sUBs):

(временно затворете антивирусната си програма):

  • Изтеглете Flash Disinfector и го запишете на десктопа.
  • Стартирайте Flash_Disinfector.exe с двоен клик. Програмата ще поиска да поставите флаш памети или подобни преносими устройства, включително мобилни телефони и камери. Следвайте инструкциите на Flash Disinfector, за да сканира и да почисти тези устройства.
  • След това рестартирайте компютъра и включете антивирусната си програма отново.
  • Вече е безопасно да поставите флашката в компютъра си, но преди да я използвайте я сканирайте за вируси с avast! от контекстното меню с десен бутон върху нея).
  • Забележка: Flash_Desinfector ще създаде скрити папки с имената - autorun.inf (със съответните файлове в тях с имената lpt3.This folder was created by Flash_Disinfector) на всички дялове на компютъра - не ги трийте, защото те са създадени за да имунизират системата срещу бъдещи зарази пристигащи чрез flash устройствата.

От още няколко съвета:

1. Редовно обновявайте антивирусната си програма и сканирайте компютъра си поне веднъж на седмица или две.

2. Редовно обновявайте и сканирайте с Malwarebytes' Anti-Malware и SUPERAntiSpyware който вече имате инсталирани на системата.

3. Редовно проверявайте за актуализации за Операционната Система чрез (Windows Update) и инсталирайте основно критичните кръпки. (ако Windows-a ви е легален разбира се).

4. Тъй като използвате основно Internet Explorer - ето няколко съвети и за него:

- Обновете го до последната версия оттук => Internet Explorer 9.0 Final за Windows Vista EN x86

- Инсталирайте SpywareBlaster 4.4 отидете на Update и натиснете Check for updates, след което се върнете на Protection Status и натиснете Enable all protection.

- Добавете EasyList чрез натискане на бутона ADD TPL Натиснете тук. Това е алтернатива на добавката Adblock Plus, която се използва в браузъра Mozilla Firefox за блокиране на реклами, банери и други неприятни и досадни джаджи по време на сърфиране.

- От бутона Safety сложете отметка пред ActiveX filtering

Публикувано изображение

- Включете и опцията Turn on SmartScreen Filter (намира се малко под ActiveX filtering).

5. Стойте настрана от непознати сайтове и торент тракери. Също така имайте впредвид, че има редица добри и безплатни приложения на повечето известни платени прогами, които вършат добра работа за домашна употреба и не е задължително непременно да се занимавате с кракове, пачове и кейгенератори в които често има и зловреден код.

Приятно и безопасно сърфиране ! :)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.