przez Mikou@j 09 Cze 2012, 19:29
Tak jak w temacie, komputerek się nie wyłącza. Proszę o sprawdzenie logów, chce wykluczyć najpierw winę infekcji.
- Kod: Zaznacz wszystko
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-06-09 19:26:55
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS543232A7A384 rev.ES2OA90B
Running: oci16et5.exe; Driver: C:\Users\Kasia\AppData\Local\Temp\kwldipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0x8B836F80]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAlpcConnectPort [0x8B83716C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0x8B8362E0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0x8B836BE6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0x8B83699A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0x8B837CE4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0x8B835CCC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThreadEx [0x8B83739A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0x8B837716]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0x8B8365A8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0x8B836DC2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0x8B836842]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0x8B837A02]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0x8B836512]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0x8B83672E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateProcess [0x8B8360E2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0x8B835ED0]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackTransaction + 13E9 81C7F599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81CA4092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 220 81CAB870 4 Bytes [80, 6F, 83, 8B] {SUB BYTE [EDI-0x7d], 0x8b}
.text ntkrnlpa.exe!RtlSidHashLookup + 248 81CAB898 4 Bytes [6C, 71, 83, 8B]
.text ntkrnlpa.exe!RtlSidHashLookup + 2DC 81CAB92C 4 Bytes [E0, 62, 83, 8B]
.text ntkrnlpa.exe!RtlSidHashLookup + 2F8 81CAB948 4 Bytes [E6, 6B, 83, 8B]
.text ntkrnlpa.exe!RtlSidHashLookup + 340 81CAB990 4 Bytes [9A, 69, 83, 8B]
.text ...
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 A60E7000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 A60E7123 629 Bytes [25, 0E, A6, FE, 05, 34, 25, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 A60E7399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F A60E73FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B A60E74AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
.text advapi32.dll!CreateProcessAsUserA 772E14FD 5 Bytes [E9, 8E, 2E, D4, 98] {JMP 0xffffffff98d42e93}
.text gdi32.dll!DeleteDC 76E16A2C 5 Bytes [E9, 8F, 21, 21, 99] {JMP 0xffffffff99212194}
.text gdi32.dll!CreateDCA 76E19975 5 Bytes [E9, 46, 03, 21, 99] {JMP 0xffffffff9921034b}
.text gdi32.dll!CreateDCW 76E1BD21 5 Bytes [E9, 9A, DE, 20, 99] {JMP 0xffffffff9920de9f}
.text gdi32.dll!GetPixel 76E1C714 5 Bytes [E9, 77, C2, 20, 99] {JMP 0xffffffff9920c27c}
.text kernel32.dll!CreateProcessW 75BE202D 5 Bytes [E9, FE, 2E, 44, 9A] {JMP 0xffffffff9a442f03}
.text kernel32.dll!CreateProcessA 75BE2062 5 Bytes [E9, 59, 3A, 44, 9A] {JMP 0xffffffff9a443a5e}
.text kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes [E9, 87, C0, 40, 9A] {JMP 0xffffffff9a40c08c}
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\sppsvc.exe[132] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\sppsvc.exe[132] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[348] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\csrss.exe[460] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 75861BA0 C:\Windows\system32\cmdcsr.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\csrss.exe[460] ntdll.dll!NtReplyWaitReceivePort 776C5500 5 Bytes JMP 75861450 C:\Windows\system32\cmdcsr.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\csrss.exe[460] ntdll.dll!NtReplyWaitReceivePortEx 776C5510 5 Bytes JMP 758617F0 C:\Windows\system32\cmdcsr.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!RegisterRawInputDevices 773A5C2F 5 Bytes JMP 10018E60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SystemParametersInfoA 773A7E90 7 Bytes JMP 1001C5F0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!EnableWindow 773AA72E 5 Bytes JMP 10017E00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!MoveWindow 773AA8C4 5 Bytes JMP 10018B80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!GetAsyncKeyState 773AC09A 5 Bytes JMP 10019080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetParent 773AC696 5 Bytes JMP 100188E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!RegisterHotKey 773AC8F9 5 Bytes JMP 100180A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!PostThreadMessageA 773ACBD1 5 Bytes JMP 1001B8E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageA 773ACC28 5 Bytes JMP 1001B3A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!PostMessageA 773AD656 5 Bytes JMP 1001BE20 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendNotifyMessageW 773AEB65 5 Bytes JMP 1001A0C0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!PostThreadMessageW 773AECDE 5 Bytes JMP 1001B640 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SystemParametersInfoW 773AEEE1 7 Bytes JMP 1001C3D0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetWindowsHookExW 773B210A 5 Bytes JMP 1001C810 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageTimeoutW 773B313E 5 Bytes JMP 1001AB80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageCallbackW 773B4DFC 1 Byte [E9]
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageCallbackW 773B4DFC 5 Bytes JMP 1001A600 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!GetKeyState 773B4FDA 5 Bytes JMP 10019330 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetWinEventHook 773B507E 5 Bytes JMP 1001C0C0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!PostMessageW 773B6225 5 Bytes JMP 1001BB80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageW 773B764C 5 Bytes JMP 1001B100 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!GetClipboardData 773C4B47 5 Bytes JMP 100182D0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendNotifyMessageA 773C67B4 5 Bytes JMP 1001A360 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!mouse_event 773C8146 5 Bytes JMP 10029670 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetClipboardViewer 773C8F4D 5 Bytes JMP 100186E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendDlgItemMessageA 773C914D 5 Bytes JMP 10019E10 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendDlgItemMessageW 773D4CFE 5 Bytes JMP 10019B60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!GetKeyboardState 773D6B3E 5 Bytes JMP 100195E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!BlockInput 773D6C84 5 Bytes JMP 100184E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SetWindowsHookExA 773D6DFA 5 Bytes JMP 1001CA80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageTimeoutA 773D6E97 5 Bytes JMP 1001AE40 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendInput 773D7055 5 Bytes JMP 10019890 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!ExitWindowsEx 773F06EF 5 Bytes JMP 10017BF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!keybd_event 773FEC9B 5 Bytes JMP 10029880 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] USER32.dll!SendMessageCallbackA 77403EEB 5 Bytes JMP 1001A8C0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!BitBlt 76E17180 5 Bytes JMP 100293E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!MaskBlt 76E1C681 5 Bytes JMP 10029130 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!StretchBlt 76E1F418 5 Bytes JMP 10028C00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] GDI32.dll!PlgBlt 76E30900 5 Bytes JMP 10028EA0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wininit.exe[520] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\csrss.exe[528] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 75861BA0 C:\Windows\system32\cmdcsr.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\csrss.exe[528] ntdll.dll!NtReplyWaitReceivePort 776C5500 5 Bytes JMP 75861450 C:\Windows\system32\cmdcsr.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\csrss.exe[528] ntdll.dll!NtReplyWaitReceivePortEx 776C5510 5 Bytes JMP 758617F0 C:\Windows\system32\cmdcsr.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] services.exe 00DA1608 4 Bytes [80, E1, 01, 10]
.text C:\Windows\system32\services.exe[580] services.exe 00DA1618 4 Bytes [60, DC, 01, 10]
.text C:\Windows\system32\services.exe[580] services.exe 00DA1638 4 Bytes [A0, E4, 01, 10]
.text C:\Windows\system32\services.exe[580] services.exe 00DA1648 4 Bytes [E0, DE, 01, 10] {LOOPNZ 0xffffffffffffffe0; ADD [EAX], EDX}
.text C:\Windows\system32\services.exe[580] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] RPCRT4.dll!RpcServerRegisterIfEx 75D72640 5 Bytes JMP 1001F060 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\services.exe[580] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\lsm.exe[608] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\wuauclt.exe[684] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] RPCRT4.dll!RpcServerRegisterIfEx 75D72640 5 Bytes JMP 1001F060 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[748] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] RPCRT4.dll!RpcServerRegisterIfEx 75D72640 5 Bytes JMP 1001F060 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[828] rpcss.dll!CoGetComCatalog 74D93A14 8 Bytes JMP ED501001
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[896] ntdll.dll!NtAllocateVirtualMemory 776C43C0 5 Bytes JMP 00530250 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[896] ntdll.dll!NtCreateFile 776C46B0 5 Bytes JMP 00549CD0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[960] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] RPCRT4.dll!RpcServerRegisterIfEx 75D72640 5 Bytes JMP 1001F060 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1212] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\spoolsv.exe[1480] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] RPCRT4.dll!RpcServerRegisterIfEx 75D72640 5 Bytes JMP 1001F060 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1512] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[1788] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\Dwm.exe[1836] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\Explorer.EXE[1924] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[2280] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] ntdll.dll!NtAllocateVirtualMemory 776C43C0 5 Bytes JMP 007752B0 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2316] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 0022B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 0021D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 0021D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 00227DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 00224F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 00225AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 00223A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 00228BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 00229CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 00229BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 00228990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxtray.exe[2324] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 00224390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 0021B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 0020D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 0020D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 00217DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 00214F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 00215AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 00213A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 00218BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 00219CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 00219BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 00218990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\hkcmd.exe[2348] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 00214390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\igfxsrvc.exe[2356] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\igfxpers.exe[2364] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2452] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2492] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] ntdll.dll!NtAllocateVirtualMemory 776C43C0 5 Bytes JMP 00577560 C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtAllocateVirtualMemory 776C43C0 5 Bytes JMP 1002ADA0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtCreateFile 776C46B0 5 Bytes JMP 1002AD60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtCreateProcess 776C4780 5 Bytes JMP 1002AE20 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtCreateProcessEx 776C4790 5 Bytes JMP 1002AE00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtDeleteFile 776C48F0 5 Bytes JMP 1002ADC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtFreeVirtualMemory 776C4AC0 5 Bytes JMP 1002A430 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtLoadDriver 776C4C40 5 Bytes JMP 1002AD80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtOpenFile 776C4DC0 5 Bytes JMP 1002AD40 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtProtectVirtualMemory 776C5000 5 Bytes JMP 1002A3E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtSetInformationProcess 776C5760 5 Bytes JMP 1002AD00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtUnloadDriver 776C5A40 5 Bytes JMP 1002AD20 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!NtWriteVirtualMemory 776C5B80 5 Bytes JMP 1002ADE0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!KiUserExceptionDispatcher 776C60E8 5 Bytes JMP 1002A6F0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!RtlAllocateHeap 776D1F25 5 Bytes JMP 1002A480 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!LdrGetProcedureAddress 776DECC7 5 Bytes JMP 1002ACE0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 6363C930 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!OpenFile 75C1412F 5 Bytes JMP 1002AC40 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CopyFileW 75C18CAF 5 Bytes JMP 1002ABC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MoveFileW 75C1A193 5 Bytes JMP 1002AB40 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CopyFileExW 75C207DB 3 Bytes JMP 1002AB80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CopyFileExW + 4 75C207DF 3 Bytes [9A, CC, CC]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!VirtualProtect 75C250CB 5 Bytes JMP 1002A9C0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!DeleteFileW 75C2658B 5 Bytes JMP 1002AA80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!DeleteFileA 75C28BD6 5 Bytes JMP 1002AAA0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!LoadLibraryExW 75C2B647 5 Bytes JMP 1002AC60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!LoadLibraryExA 75C2BC13 5 Bytes JMP 1002AC80 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MoveFileWithProgressW 75C2BE8C 5 Bytes JMP 1002AAC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MoveFileExW 75C2BEB0 5 Bytes JMP 1002AB00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MapViewOfFile 75C2C05C 5 Bytes JMP 6386E083 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!VirtualAlloc 75C30594 5 Bytes JMP 6386E0AA C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CreateFileW 75C30AFD 5 Bytes JMP 1002AC00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!GetProcAddress 75C317D7 5 Bytes JMP 1002ACC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!GetModuleHandleW 75C31941 5 Bytes JMP 1002AA40 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!LoadLibraryA 75C32804 5 Bytes JMP 1002AA20 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!LoadLibraryW 75C32852 5 Bytes JMP 1002AA00 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!GetModuleHandleA 75C32877 5 Bytes JMP 1002AA60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CreateFileA 75C3289C 5 Bytes JMP 1002AC20 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MoveFileExA 75C42F8B 5 Bytes JMP 1002AB20 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MoveFileWithProgressA 75C42FAB 5 Bytes JMP 1002AAE0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CopyFileA 75C47C94 5 Bytes JMP 1002ABE0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!MoveFileA 75C6AD41 5 Bytes JMP 1002AB60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!CopyFileExA 75C6BB99 5 Bytes JMP 1002ABA0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!WinExec 75C6E739 5 Bytes JMP 1002A9E0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] kernel32.dll!LoadModule 75C6EC52 5 Bytes JMP 1002ACA0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] GDI32.dll!CreateDIBSection 76E185F0 4 Bytes JMP 6386E00D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2760] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\SearchIndexer.exe[2848] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2988] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\LogonUI.exe[2996] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[3260] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[3384] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\oci16et5.exe[4736] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\taskhost.exe[4904] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\System32\svchost.exe[5260] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Users\Kasia\Desktop\OTL.exe[5444] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5668] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\notepad.exe[5912] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] ntdll.dll!NtAlpcSendWaitReceivePort 776C4500 5 Bytes JMP 1002B520 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] ntdll.dll!NtClose 776C45B0 5 Bytes JMP 1001D080 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] ntdll.dll!LdrUnloadDll 776DBD1F 7 Bytes JMP 1001D1A0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] ntdll.dll!LdrLoadDll 776DF425 5 Bytes JMP 10027DF0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] kernel32.dll!CreateProcessW 75BE202D 5 Bytes JMP 10024F30 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] kernel32.dll!CreateProcessA 75BE2062 5 Bytes JMP 10025AC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] kernel32.dll!CreateProcessAsUserW 75C179D4 5 Bytes JMP 10023A60 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] GDI32.dll!DeleteDC 76E16A2C 5 Bytes JMP 10028BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] GDI32.dll!CreateDCA 76E19975 5 Bytes JMP 10029CC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] GDI32.dll!CreateDCW 76E1BD21 5 Bytes JMP 10029BC0 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] GDI32.dll!GetPixel 76E1C714 5 Bytes JMP 10028990 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Windows\system32\svchost.exe[5964] ADVAPI32.dll!CreateProcessAsUserA 772E14FD 5 Bytes JMP 10024390 C:\Windows\system32\guard32.dll (COMODO Internet Security/COMODO)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [006573C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [00656AA0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] [006574C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [00657380] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [00657440] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [00657550] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [00657400] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!DeleteObject] [00656200] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!RegisterClassA] [00656B30] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!RegisterClassW] [00656BF0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [006561A0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [00656690] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [00656600] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSystemMetrics] [00656CB0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [00656250] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DrawFrameControl] [00657180] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DrawEdge] [00657130] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetScrollInfo] [00656450] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!SystemParametersInfoW] [00656E30] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [00656F70] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!SetScrollInfo] [00656340] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [006564C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!SetScrollPos] [006562B0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [006561A0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!RegisterClassW] [00656BF0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [006570B0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [00656690] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSystemMetrics] [00656CB0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!DeleteObject] [00656200] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [00657380] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [006573C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [00657440] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [00657550] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [00657380] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [006573C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [00657400] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [GDI32.dll!DeleteObject] [00656200] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [USER32.dll!CallWindowProcW] [006564C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSysColor] [006561A0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSystemMetrics] [00656CB0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [USER32.dll!SystemParametersInfoW] [00656E30] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [USER32.dll!RegisterClassW] [00656BF0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [USER32.dll!DefWindowProcW] [00656690] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [006573C0] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [00657380] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [00657440] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [00657400] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [00657380] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [00657550] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryExA] [00657400] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2288] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [00657550] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0048B870] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0048AF50] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] [0048B970] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0048B830] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0048B8F0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [0048BA00] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0048B8B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!DeleteObject] [0048A6B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!RegisterClassA] [0048AFE0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!RegisterClassW] [0048B0A0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [0048A650] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [0048AB40] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [0048AAB0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSystemMetrics] [0048B160] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [0048A700] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DrawFrameControl] [0048B630] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DrawEdge] [0048B5E0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetScrollInfo] [0048A900] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!SystemParametersInfoW] [0048B2E0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [0048B420] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!SetScrollInfo] [0048A7F0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [0048A970] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!SetScrollPos] [0048A760] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [0048A650] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!RegisterClassW] [0048B0A0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [0048B560] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [0048AB40] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSystemMetrics] [0048B160] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!DeleteObject] [0048A6B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0048B830] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0048B870] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0048B8F0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [0048BA00] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0048B830] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0048B870] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [0048B8B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [GDI32.dll!DeleteObject] [0048A6B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [USER32.dll!CallWindowProcW] [0048A970] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSysColor] [0048A650] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSystemMetrics] [0048B160] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [USER32.dll!SystemParametersInfoW] [0048B2E0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [USER32.dll!RegisterClassW] [0048B0A0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [USER32.dll!DefWindowProcW] [0048AB40] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0048B870] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0048B830] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [0048B8F0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [0048B8B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0048B830] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [0048BA00] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryExA] [0048B8B0] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe[2580] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [0048BA00] C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe (COMODO Internet Security/COMODO)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Aparat wykonawczy struktury sterowników trybu jądra/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Aparat wykonawczy struktury sterowników trybu jądra/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
Device \Driver\ACPI_HAL \Device\00000049 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Menedżer filtrów systemu plików firmy Microsoft/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:5980] A60F4F2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ?????????????d?1????|???\?l??????H?????????????????????????????? ??????? ??????? ???????battery.inf_x86_neutral_5752155055c5e2d7????????WUDFRd?l:6??@%systemroot%\system32\rascfg.dll,-32002????? ???????????????????????????????????????b??????????????battery.inf_x86_neutral_5752155055c5e2d7?????????????k?????????????s?k???p??*teredo??~??USB DISK?2??.NT? @???????????????????0??h????????????????????????????????????????0??????????????????????????????????????????????????????????????? ??????????????????????????????,?????1e??????$??????????????:\$Recycle.Bin\*???? $??????h?????col???:\$Recycle.Bin\*?????,?????????????????Os==Vista || Os==Win7???? ????????????????????????????????????2xe???????0???1???2??429??C:\Users\Kasia\AppData\Local\Microsoft\Windows\Temporary Internet Files\*???? ??????????????????C:\Users\Kasia\AppData\Local\Microsoft\Windows\Temporary Internet Files\*???????????? ?mmc??? ??????????????????????????????N?????????????N????????DC9??{650182C5-F067-4B2C-AFFC-824D417EC7D6}????????2?????????C:??Pliki l
---- Files - GMER 1.0.15 ----
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\01FC5CE0-BA98-4421-AD77-BCA3182A5C42.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\01FC5CE0-BA98-4421-AD77-BCA3182A5C42.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\098699F3-5DB5-45DD-9822-A3926C374B9E.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\098699F3-5DB5-45DD-9822-A3926C374B9E.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\0E24D715-4919-41BD-82BD-E1770CEF3471.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\0E24D715-4919-41BD-82BD-E1770CEF3471.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\3DDD4577-9B4D-4D65-B1EF-3AB12F7D75EF.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\3DDD4577-9B4D-4D65-B1EF-3AB12F7D75EF.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\42C20FDC-8567-4A5E-844E-3CEFC46C75B8.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\92F98077-D6B0-4603-9B7D-AA507BB8987A.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\92F98077-D6B0-4603-9B7D-AA507BB8987A.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\92FEC819-2A01-4724-AAEC-55FD528EA97B.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\92FEC819-2A01-4724-AAEC-55FD528EA97B.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\940935F4-CF15-4F99-BE59-6379D275722B.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\940935F4-CF15-4F99-BE59-6379D275722B.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\9C3EB5E4-01F8-40E4-9CDF-AA7E69265E6D.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\9C3EB5E4-01F8-40E4-9CDF-AA7E69265E6D.data.info 304 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\C10D4807-44C2-4B9B-9755-309C2C9CE0F3.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\C10D4807-44C2-4B9B-9755-309C2C9CE0F3.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\D06E946B-46BF-4AEA-9BF4-5A9D712C8922.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\D06E946B-46BF-4AEA-9BF4-5A9D712C8922.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\435775FF-1B46-47BB-93D7-02FFC7C3249A.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\435775FF-1B46-47BB-93D7-02FFC7C3249A.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\4B989ACE-8000-4D69-8EA8-B56C416FE1E6.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\4B989ACE-8000-4D69-8EA8-B56C416FE1E6.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\5AA2C755-684E-44C0-9FFB-4B6D6DBF084E.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\5AA2C755-684E-44C0-9FFB-4B6D6DBF084E.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\D4F06C61-11B4-46C0-AB41-AFC5EBFD94AD.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\DA07EA07-109A-4450-B462-1A5C5148B363.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\DA07EA07-109A-4450-B462-1A5C5148B363.data.info 154 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F3E3E8BB-9B1E-4C11-8C3D-FB2F49A54610.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F3E3E8BB-9B1E-4C11-8C3D-FB2F49A54610.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F4926F30-0CAF-4A48-8956-C90AAC470CFE.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F4926F30-0CAF-4A48-8956-C90AAC470CFE.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\FDDB72A5-45E2-42D1-8FB6-496A7A488367.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\FDDB72A5-45E2-42D1-8FB6-496A7A488367.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\Temp 0 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\Temp\baseupd 0 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\42C20FDC-8567-4A5E-844E-3CEFC46C75B8.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\6513AB5A-C685-48A4-AD03-FECFB513C0C1.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\8BA213E5-6154-4160-BF91-9485EBC4C879.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\D4F06C61-11B4-46C0-AB41-AFC5EBFD94AD.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\6513AB5A-C685-48A4-AD03-FECFB513C0C1.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\7E3767D4-DBE7-4E79-B7BF-34E6D178C49D.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\7E3767D4-DBE7-4E79-B7BF-34E6D178C49D.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\7F9319BC-5DA7-415D-8204-9000D8327068.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\7F9319BC-5DA7-415D-8204-9000D8327068.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\81636839-DAFC-46D5-885F-45A31B16B5A1.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\81636839-DAFC-46D5-885F-45A31B16B5A1.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\87849E2E-C7D5-45F5-ADBF-718712231D26.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\87849E2E-C7D5-45F5-ADBF-718712231D26.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\8866C9B5-8036-4117-BBD8-241421797422.data 11443832 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\8866C9B5-8036-4117-BBD8-241421797422.data.info 156 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\8BA213E5-6154-4160-BF91-9485EBC4C879.data 11443832 bytes executable
---- EOF - GMER 1.0.15 ----
- Załączniki
-
Extras.Txt
- (26.16 KiB) Ściągnięto 13 razy
-
OTL.Txt
- (40.34 KiB) Ściągnięto 17 razy
ASUS TUF Gaming FX505DT R5-3550H/16GB || XBOX ONE + LG 43UJ6307 || Nintendo Switch ||
"Nothing is true, everything is permitted"NIE POMAGAM NA PW 