GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-07-18 19:40:59
Windows 6.1.7600  Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0
Running: p6x3vcrc.exe; Driver: C:\Users\Bilu\AppData\Local\Temp\aftcyaog.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwAddBootEntry [0x90A4E202]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                           ZwAllocateVirtualMemory [0x91623C48]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateEvent [0x90A507F0]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateEventPair [0x90A50848]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateIoCompletion [0x90A5095E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateMutant [0x90A50746]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateSection [0x90A50898]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateSemaphore [0x90A5079A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwCreateTimer [0x90A5090C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwDeleteBootEntry [0x90A4E226]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                           ZwFreeVirtualMemory [0x91623CF8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwLoadDriver [0x90A4DFF0]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwModifyBootEntry [0x90A4E24A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwNotifyChangeKey [0x90A50D56]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwNotifyChangeMultipleKeys [0x90A4ECDA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenEvent [0x90A50820]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenEventPair [0x90A50870]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenIoCompletion [0x90A50988]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenMutant [0x90A50772]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenSection [0x90A508D8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenSemaphore [0x90A507C8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwOpenTimer [0x90A50936]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                           ZwProtectVirtualMemory [0x91623D90]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwQueryObject [0x90A4EBA0]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwSetBootEntryOrder [0x90A4E26E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwSetBootOptions [0x90A4E292]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwSetSystemInformation [0x90A4E04A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwSetSystemPowerState [0x90A4E186]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwShutdownSystem [0x90A4E162]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwSystemDebugControl [0x90A4E1AA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                           ZwVdmControl [0x90A4E2B6]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                           ZwCreateProcessEx [0x91639762]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                           ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!ZwRollbackTransaction + 13E9                                                                                                       83886599 1 Byte  [06]
.text           ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                                                          838AB092 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text           ntkrnlpa.exe!RtlSidHashLookup + 214                                                                                                             838B2864 4 Bytes  [02, E2, A4, 90] {ADD AH, DL; MOVSB ; NOP }
.text           ntkrnlpa.exe!RtlSidHashLookup + 23C                                                                                                             838B288C 4 Bytes  [48, 3C, 62, 91] {DEC EAX; CMP AL, 0x62; XCHG ECX, EAX}
.text           ntkrnlpa.exe!RtlSidHashLookup + 2F0                                                                                                             838B2940 8 Bytes  [F0, 07, A5, 90, 48, 08, A5, ...]
.text           ntkrnlpa.exe!RtlSidHashLookup + 2FC                                                                                                             838B294C 4 Bytes  [5E, 09, A5, 90]
.text           ntkrnlpa.exe!RtlSidHashLookup + 318                                                                                                             838B2968 4 Bytes  [46, 07, A5, 90] {INC ESI; POP ES; MOVSD ; NOP }
.text           ...                                                                                                                                             
PAGE            ntkrnlpa.exe!ObMakeTemporaryObject                                                                                                              83A4C3BE 5 Bytes  JMP 9163511E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntkrnlpa.exe!ObInsertObject + 27                                                                                                                83A660CD 5 Bytes  JMP 91636BD4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108                                                                                                     83AB0762 4 Bytes  CALL 90A4F34B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122                                                                                                    83AB8873 4 Bytes  CALL 90A4F361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            ntkrnlpa.exe!ZwCreateProcessEx                                                                                                                  83B1E4DE 7 Bytes  JMP 91639766 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text           user32.dll!UnhookWindowsHookEx                                                                                                                  7766CC7B 5 Bytes  [E9, 88, 3D, BA, 88] {JMP 0xffffffff88ba3d8d}
.text           user32.dll!UnhookWinEvent                                                                                                                       7766D924 5 Bytes  [E9, D3, 2A, BA, 88] {JMP 0xffffffff88ba2ad8}
.text           user32.dll!SetWindowsHookExW                                                                                                                    7767210A 5 Bytes  [E9, F5, E6, B9, 88] {JMP 0xffffffff88b9e6fa}
.text           user32.dll!SetWinEventHook                                                                                                                      7767507E 5 Bytes  [E9, 75, B1, B9, 88] {JMP 0xffffffff88b9b17a}
.text           user32.dll!SetWindowsHookExA                                                                                                                    77696DFA 5 Bytes  [E9, 01, 98, B7, 88] {JMP 0xffffffff88b79806}
.text           kernel32.dll!GetBinaryTypeW + 70                                                                                                                76F978FC 1 Byte  [62]

---- User code sections - GMER 1.0.15 ----

.text           C:\windows\system32\srvany.exe[352] ntdll.dll!LdrUnloadDll                                                                                      778EBD1F 5 Bytes  JMP 000903FC 
.text           C:\windows\system32\srvany.exe[352] ntdll.dll!LdrLoadDll                                                                                        778EF425 5 Bytes  JMP 000901F8 
.text           C:\windows\system32\srvany.exe[352] kernel32.dll!GetBinaryTypeW + 70                                                                            76F978FC 1 Byte  [62]
.text           C:\windows\system32\srvany.exe[352] USER32.dll!UnhookWindowsHookEx                                                                              7766CC7B 5 Bytes  JMP 00120A08 
.text           C:\windows\system32\srvany.exe[352] USER32.dll!UnhookWinEvent                                                                                   7766D924 5 Bytes  JMP 001203FC 
.text           C:\windows\system32\srvany.exe[352] USER32.dll!SetWindowsHookExW                                                                                7767210A 5 Bytes  JMP 00120804 
.text           C:\windows\system32\srvany.exe[352] USER32.dll!SetWinEventHook                                                                                  7767507E 5 Bytes  JMP 001201F8 
.text           C:\windows\system32\srvany.exe[352] USER32.dll!SetWindowsHookExA                                                                                77696DFA 5 Bytes  JMP 00120600 
.text           C:\windows\system32\csrss.exe[464] kernel32.dll!GetBinaryTypeW + 70                                                                             76F978FC 1 Byte  [62]
.text           C:\windows\KMService.exe[476] ntdll.dll!LdrUnloadDll                                                                                            778EBD1F 5 Bytes  JMP 001903FC 
.text           C:\windows\KMService.exe[476] ntdll.dll!LdrLoadDll                                                                                              778EF425 5 Bytes  JMP 001901F8 
.text           C:\windows\KMService.exe[476] kernel32.dll!GetBinaryTypeW + 70                                                                                  76F978FC 1 Byte  [62]
.text           C:\windows\KMService.exe[476] USER32.dll!UnhookWindowsHookEx                                                                                    7766CC7B 5 Bytes  JMP 001A0A08 
.text           C:\windows\KMService.exe[476] USER32.dll!UnhookWinEvent                                                                                         7766D924 5 Bytes  JMP 001A03FC 
.text           C:\windows\KMService.exe[476] USER32.dll!SetWindowsHookExW                                                                                      7767210A 5 Bytes  JMP 001A0804 
.text           C:\windows\KMService.exe[476] USER32.dll!SetWinEventHook                                                                                        7767507E 5 Bytes  JMP 001A01F8 
.text           C:\windows\KMService.exe[476] USER32.dll!SetWindowsHookExA                                                                                      77696DFA 5 Bytes  JMP 001A0600 
.text           C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe[508] KERNEL32.dll!GetBinaryTypeW + 70                            76F978FC 1 Byte  [62]
.text           C:\windows\system32\wininit.exe[536] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000303FC 
.text           C:\windows\system32\wininit.exe[536] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000301F8 
.text           C:\windows\system32\wininit.exe[536] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\system32\wininit.exe[536] USER32.dll!UnhookWindowsHookEx                                                                             7766CC7B 5 Bytes  JMP 000C0A08 
.text           C:\windows\system32\wininit.exe[536] USER32.dll!UnhookWinEvent                                                                                  7766D924 5 Bytes  JMP 000C03FC 
.text           C:\windows\system32\wininit.exe[536] USER32.dll!SetWindowsHookExW                                                                               7767210A 5 Bytes  JMP 000C0804 
.text           C:\windows\system32\wininit.exe[536] USER32.dll!SetWinEventHook                                                                                 7767507E 5 Bytes  JMP 000C01F8 
.text           C:\windows\system32\wininit.exe[536] USER32.dll!SetWindowsHookExA                                                                               77696DFA 5 Bytes  JMP 000C0600 
.text           C:\windows\system32\csrss.exe[544] kernel32.dll!GetBinaryTypeW + 70                                                                             76F978FC 1 Byte  [62]
.text           C:\windows\system32\services.exe[592] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\services.exe[592] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\services.exe[592] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\lsass.exe[612] ntdll.dll!LdrUnloadDll                                                                                       778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\lsass.exe[612] ntdll.dll!LdrLoadDll                                                                                         778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\lsass.exe[612] kernel32.dll!GetBinaryTypeW + 70                                                                             76F978FC 1 Byte  [62]
.text           C:\windows\system32\lsm.exe[624] ntdll.dll!LdrUnloadDll                                                                                         778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\lsm.exe[624] ntdll.dll!LdrLoadDll                                                                                           778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\lsm.exe[624] kernel32.dll!GetBinaryTypeW + 70                                                                               76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[712] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[712] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[712] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\system32\nvvsvc.exe[796] ntdll.dll!LdrUnloadDll                                                                                      778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\windows\system32\nvvsvc.exe[796] ntdll.dll!LdrLoadDll                                                                                        778EF425 5 Bytes  JMP 001601F8 
.text           C:\windows\system32\nvvsvc.exe[796] kernel32.dll!GetBinaryTypeW + 70                                                                            76F978FC 1 Byte  [62]
.text           C:\windows\system32\nvvsvc.exe[796] USER32.dll!UnhookWindowsHookEx                                                                              7766CC7B 5 Bytes  JMP 002F0A08 
.text           C:\windows\system32\nvvsvc.exe[796] USER32.dll!UnhookWinEvent                                                                                   7766D924 5 Bytes  JMP 002F03FC 
.text           C:\windows\system32\nvvsvc.exe[796] USER32.dll!SetWindowsHookExW                                                                                7767210A 5 Bytes  JMP 002F0804 
.text           C:\windows\system32\nvvsvc.exe[796] USER32.dll!SetWinEventHook                                                                                  7767507E 5 Bytes  JMP 002F01F8 
.text           C:\windows\system32\nvvsvc.exe[796] USER32.dll!SetWindowsHookExA                                                                                77696DFA 5 Bytes  JMP 002F0600 
.text           C:\windows\system32\svchost.exe[836] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[836] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[836] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\system32\conhost.exe[852] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000703FC 
.text           C:\windows\system32\conhost.exe[852] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000701F8 
.text           C:\windows\system32\conhost.exe[852] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\system32\conhost.exe[852] USER32.dll!UnhookWindowsHookEx                                                                             7766CC7B 5 Bytes  JMP 00100A08 
.text           C:\windows\system32\conhost.exe[852] USER32.dll!UnhookWinEvent                                                                                  7766D924 5 Bytes  JMP 001003FC 
.text           C:\windows\system32\conhost.exe[852] USER32.dll!SetWindowsHookExW                                                                               7767210A 5 Bytes  JMP 00100804 
.text           C:\windows\system32\conhost.exe[852] USER32.dll!SetWinEventHook                                                                                 7767507E 5 Bytes  JMP 001001F8 
.text           C:\windows\system32\conhost.exe[852] USER32.dll!SetWindowsHookExA                                                                               77696DFA 5 Bytes  JMP 00100600 
.text           C:\windows\System32\svchost.exe[900] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\System32\svchost.exe[900] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\System32\svchost.exe[900] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\System32\svchost.exe[900] USER32.dll!UnhookWindowsHookEx                                                                             7766CC7B 5 Bytes  JMP 00240A08 
.text           C:\windows\System32\svchost.exe[900] USER32.dll!UnhookWinEvent                                                                                  7766D924 5 Bytes  JMP 002403FC 
.text           C:\windows\System32\svchost.exe[900] USER32.dll!SetWindowsHookExW                                                                               7767210A 5 Bytes  JMP 00240804 
.text           C:\windows\System32\svchost.exe[900] USER32.dll!SetWinEventHook                                                                                 7767507E 5 Bytes  JMP 002401F8 
.text           C:\windows\System32\svchost.exe[900] USER32.dll!SetWindowsHookExA                                                                               77696DFA 5 Bytes  JMP 00240600 
.text           C:\windows\System32\svchost.exe[932] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\System32\svchost.exe[932] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\System32\svchost.exe[932] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\System32\svchost.exe[932] USER32.dll!UnhookWindowsHookEx                                                                             7766CC7B 5 Bytes  JMP 00590A08 
.text           C:\windows\System32\svchost.exe[932] USER32.dll!UnhookWinEvent                                                                                  7766D924 5 Bytes  JMP 005903FC 
.text           C:\windows\System32\svchost.exe[932] USER32.dll!SetWindowsHookExW                                                                               7767210A 5 Bytes  JMP 00590804 
.text           C:\windows\System32\svchost.exe[932] USER32.dll!SetWinEventHook                                                                                 7767507E 5 Bytes  JMP 005901F8 
.text           C:\windows\System32\svchost.exe[932] USER32.dll!SetWindowsHookExA                                                                               77696DFA 5 Bytes  JMP 00590600 
.text           C:\windows\system32\svchost.exe[972] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[972] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[972] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[972] USER32.dll!UnhookWindowsHookEx                                                                             7766CC7B 5 Bytes  JMP 00FC0A08 
.text           C:\windows\system32\svchost.exe[972] USER32.dll!UnhookWinEvent                                                                                  7766D924 5 Bytes  JMP 00FC03FC 
.text           C:\windows\system32\svchost.exe[972] USER32.dll!SetWindowsHookExW                                                                               7767210A 5 Bytes  JMP 00FC0804 
.text           C:\windows\system32\svchost.exe[972] USER32.dll!SetWinEventHook                                                                                 7767507E 5 Bytes  JMP 00FC01F8 
.text           C:\windows\system32\svchost.exe[972] USER32.dll!SetWindowsHookExA                                                                               77696DFA 5 Bytes  JMP 00FC0600 
.text           C:\windows\system32\AUDIODG.EXE[1036] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[1076] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[1076] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[1076] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[1076] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00450A08 
.text           C:\windows\system32\svchost.exe[1076] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 004503FC 
.text           C:\windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00450804 
.text           C:\windows\system32\svchost.exe[1076] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 004501F8 
.text           C:\windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00450600 
.text           C:\windows\system32\svchost.exe[1164] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000A03FC 
.text           C:\windows\system32\svchost.exe[1164] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000A01F8 
.text           C:\windows\system32\svchost.exe[1164] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[1164] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00A10A08 
.text           C:\windows\system32\svchost.exe[1164] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 00A103FC 
.text           C:\windows\system32\svchost.exe[1164] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00A10804 
.text           C:\windows\system32\svchost.exe[1164] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 00A101F8 
.text           C:\windows\system32\svchost.exe[1164] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00A10600 
.text           C:\windows\system32\winlogon.exe[1260] ntdll.dll!LdrUnloadDll                                                                                   778EBD1F 5 Bytes  JMP 000303FC 
.text           C:\windows\system32\winlogon.exe[1260] ntdll.dll!LdrLoadDll                                                                                     778EF425 5 Bytes  JMP 000301F8 
.text           C:\windows\system32\winlogon.exe[1260] kernel32.dll!GetBinaryTypeW + 70                                                                         76F978FC 1 Byte  [62]
.text           C:\windows\system32\winlogon.exe[1260] USER32.dll!UnhookWindowsHookEx                                                                           7766CC7B 5 Bytes  JMP 000C0A08 
.text           C:\windows\system32\winlogon.exe[1260] USER32.dll!UnhookWinEvent                                                                                7766D924 5 Bytes  JMP 000C03FC 
.text           C:\windows\system32\winlogon.exe[1260] USER32.dll!SetWindowsHookExW                                                                             7767210A 5 Bytes  JMP 000C0804 
.text           C:\windows\system32\winlogon.exe[1260] USER32.dll!SetWinEventHook                                                                               7767507E 5 Bytes  JMP 000C01F8 
.text           C:\windows\system32\winlogon.exe[1260] USER32.dll!SetWindowsHookExA                                                                             77696DFA 5 Bytes  JMP 000C0600 
.text           C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1296] kernel32.dll!SetUnhandledExceptionFilter                                              76F830E2 4 Bytes  [C2, 04, 00, 90] {RET 0x4; NOP }
.text           C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1296] kernel32.dll!GetBinaryTypeW + 70                                                      76F978FC 1 Byte  [62]
.text           C:\windows\SYSTEM32\Rezip.exe[1420] ntdll.dll!LdrUnloadDll                                                                                      778EBD1F 5 Bytes  JMP 001503FC 
.text           C:\windows\SYSTEM32\Rezip.exe[1420] ntdll.dll!LdrLoadDll                                                                                        778EF425 5 Bytes  JMP 001501F8 
.text           C:\windows\SYSTEM32\Rezip.exe[1420] kernel32.dll!GetBinaryTypeW + 70                                                                            76F978FC 1 Byte  [62]
.text           C:\windows\SYSTEM32\Rezip.exe[1420] USER32.dll!UnhookWindowsHookEx                                                                              7766CC7B 5 Bytes  JMP 001E0A08 
.text           C:\windows\SYSTEM32\Rezip.exe[1420] USER32.dll!UnhookWinEvent                                                                                   7766D924 5 Bytes  JMP 001E03FC 
.text           C:\windows\SYSTEM32\Rezip.exe[1420] USER32.dll!SetWindowsHookExW                                                                                7767210A 5 Bytes  JMP 001E0804 
.text           C:\windows\SYSTEM32\Rezip.exe[1420] USER32.dll!SetWinEventHook                                                                                  7767507E 5 Bytes  JMP 001E01F8 
.text           C:\windows\SYSTEM32\Rezip.exe[1420] USER32.dll!SetWindowsHookExA                                                                                77696DFA 5 Bytes  JMP 001E0600 
.text           C:\windows\system32\nvvsvc.exe[1484] ntdll.dll!LdrUnloadDll                                                                                     778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\windows\system32\nvvsvc.exe[1484] ntdll.dll!LdrLoadDll                                                                                       778EF425 5 Bytes  JMP 001601F8 
.text           C:\windows\system32\nvvsvc.exe[1484] kernel32.dll!GetBinaryTypeW + 70                                                                           76F978FC 1 Byte  [62]
.text           C:\windows\system32\nvvsvc.exe[1484] USER32.dll!UnhookWindowsHookEx                                                                             7766CC7B 5 Bytes  JMP 00180A08 
.text           C:\windows\system32\nvvsvc.exe[1484] USER32.dll!UnhookWinEvent                                                                                  7766D924 5 Bytes  JMP 001803FC 
.text           C:\windows\system32\nvvsvc.exe[1484] USER32.dll!SetWindowsHookExW                                                                               7767210A 5 Bytes  JMP 00180804 
.text           C:\windows\system32\nvvsvc.exe[1484] USER32.dll!SetWinEventHook                                                                                 7767507E 5 Bytes  JMP 001801F8 
.text           C:\windows\system32\nvvsvc.exe[1484] USER32.dll!SetWindowsHookExA                                                                               77696DFA 5 Bytes  JMP 00180600 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] ntdll.dll!LdrUnloadDll                                                              778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] ntdll.dll!LdrLoadDll                                                                778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] kernel32.dll!GetBinaryTypeW + 70                                                    76F978FC 1 Byte  [62]
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] USER32.dll!UnhookWindowsHookEx                                                      7766CC7B 5 Bytes  JMP 001F0A08 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] USER32.dll!UnhookWinEvent                                                           7766D924 5 Bytes  JMP 001F03FC 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] USER32.dll!SetWindowsHookExW                                                        7767210A 5 Bytes  JMP 001F0804 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] USER32.dll!SetWinEventHook                                                          7767507E 5 Bytes  JMP 001F01F8 
.text           C:\Program Files\CyberLink\Shared files\RichVideo.exe[1520] USER32.dll!SetWindowsHookExA                                                        77696DFA 5 Bytes  JMP 001F0600 
.text           C:\windows\system32\svchost.exe[1544] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[1544] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[1544] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\System32\spoolsv.exe[1848] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000B03FC 
.text           C:\windows\System32\spoolsv.exe[1848] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000B01F8 
.text           C:\windows\System32\spoolsv.exe[1848] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\System32\spoolsv.exe[1848] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00190A08 
.text           C:\windows\System32\spoolsv.exe[1848] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 001903FC 
.text           C:\windows\System32\spoolsv.exe[1848] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00190804 
.text           C:\windows\System32\spoolsv.exe[1848] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 001901F8 
.text           C:\windows\System32\spoolsv.exe[1848] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00190600 
.text           C:\windows\system32\svchost.exe[1912] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[1912] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[1912] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[1912] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00220A08 
.text           C:\windows\system32\svchost.exe[1912] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 002203FC 
.text           C:\windows\system32\svchost.exe[1912] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00220804 
.text           C:\windows\system32\svchost.exe[1912] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 002201F8 
.text           C:\windows\system32\svchost.exe[1912] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00220600 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] ntdll.dll!LdrUnloadDll                             778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] ntdll.dll!LdrLoadDll                               778EF425 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] kernel32.dll!GetBinaryTypeW + 70                   76F978FC 1 Byte  [62]
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] USER32.dll!UnhookWindowsHookEx                     7766CC7B 5 Bytes  JMP 00100A08 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] USER32.dll!UnhookWinEvent                          7766D924 5 Bytes  JMP 001003FC 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] USER32.dll!SetWindowsHookExW                       7767210A 5 Bytes  JMP 00100804 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] USER32.dll!SetWinEventHook                         7767507E 5 Bytes  JMP 001001F8 
.text           C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2016] USER32.dll!SetWindowsHookExA                       77696DFA 5 Bytes  JMP 00100600 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] ntdll.dll!LdrUnloadDll                                                                         778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] ntdll.dll!LdrLoadDll                                                                           778EF425 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] kernel32.dll!GetBinaryTypeW + 70                                                               76F978FC 1 Byte  [62]
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] USER32.dll!UnhookWindowsHookEx                                                                 7766CC7B 5 Bytes  JMP 00210A08 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] USER32.dll!UnhookWinEvent                                                                      7766D924 5 Bytes  JMP 002103FC 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] USER32.dll!SetWindowsHookExW                                                                   7767210A 5 Bytes  JMP 00210804 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] USER32.dll!SetWinEventHook                                                                     7767507E 5 Bytes  JMP 002101F8 
.text           C:\Program Files\Bonjour\mDNSResponder.exe[2044] USER32.dll!SetWindowsHookExA                                                                   77696DFA 5 Bytes  JMP 00210600 
.text           C:\windows\System32\svchost.exe[2072] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000A03FC 
.text           C:\windows\System32\svchost.exe[2072] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000A01F8 
.text           C:\windows\System32\svchost.exe[2072] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\System32\svchost.exe[2072] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00120A08 
.text           C:\windows\System32\svchost.exe[2072] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 001203FC 
.text           C:\windows\System32\svchost.exe[2072] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00120804 
.text           C:\windows\System32\svchost.exe[2072] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 001201F8 
.text           C:\windows\System32\svchost.exe[2072] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00120600 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] ntdll.dll!LdrUnloadDll                                            778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] ntdll.dll!LdrLoadDll                                              778EF425 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] kernel32.dll!GetBinaryTypeW + 70                                  76F978FC 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] USER32.dll!UnhookWindowsHookEx                                    7766CC7B 5 Bytes  JMP 00280A08 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] USER32.dll!UnhookWinEvent                                         7766D924 5 Bytes  JMP 002803FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] USER32.dll!SetWindowsHookExW                                      7767210A 5 Bytes  JMP 00280804 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] USER32.dll!SetWinEventHook                                        7767507E 5 Bytes  JMP 002801F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2100] USER32.dll!SetWindowsHookExA                                      77696DFA 5 Bytes  JMP 00280600 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] ntdll.dll!LdrUnloadDll                                                                               778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] ntdll.dll!LdrLoadDll                                                                                 778EF425 5 Bytes  JMP 001601F8 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] kernel32.dll!GetBinaryTypeW + 70                                                                     76F978FC 1 Byte  [62]
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] USER32.dll!UnhookWindowsHookEx                                                                       7766CC7B 5 Bytes  JMP 00210A08 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] USER32.dll!UnhookWinEvent                                                                            7766D924 5 Bytes  JMP 002103FC 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] USER32.dll!SetWindowsHookExW                                                                         7767210A 5 Bytes  JMP 00210804 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] USER32.dll!SetWinEventHook                                                                           7767507E 5 Bytes  JMP 002101F8 
.text           C:\Users\Bilu\Downloads\p6x3vcrc.exe[2108] USER32.dll!SetWindowsHookExA                                                                         77696DFA 5 Bytes  JMP 00210600 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] ntdll.dll!LdrUnloadDll                                                                          778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] ntdll.dll!LdrLoadDll                                                                            778EF425 5 Bytes  JMP 000601F8 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] kernel32.dll!GetBinaryTypeW + 70                                                                76F978FC 1 Byte  [62]
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] USER32.dll!UnhookWindowsHookEx                                                                  7766CC7B 5 Bytes  JMP 00100A08 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] USER32.dll!UnhookWinEvent                                                                       7766D924 5 Bytes  JMP 001003FC 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] USER32.dll!SetWindowsHookExW                                                                    7767210A 5 Bytes  JMP 00100804 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] USER32.dll!SetWinEventHook                                                                      7767507E 5 Bytes  JMP 001001F8 
.text           C:\Program Files\iPod\bin\iPodService.exe[2520] USER32.dll!SetWindowsHookExA                                                                    77696DFA 5 Bytes  JMP 00100600 
.text           C:\windows\system32\SearchIndexer.exe[2536] ntdll.dll!LdrUnloadDll                                                                              778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\SearchIndexer.exe[2536] ntdll.dll!LdrLoadDll                                                                                778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\SearchIndexer.exe[2536] kernel32.dll!GetBinaryTypeW + 70                                                                    76F978FC 1 Byte  [62]
.text           C:\windows\system32\SearchIndexer.exe[2536] USER32.dll!UnhookWindowsHookEx                                                                      7766CC7B 5 Bytes  JMP 00090A08 
.text           C:\windows\system32\SearchIndexer.exe[2536] USER32.dll!UnhookWinEvent                                                                           7766D924 5 Bytes  JMP 000903FC 
.text           C:\windows\system32\SearchIndexer.exe[2536] USER32.dll!SetWindowsHookExW                                                                        7767210A 5 Bytes  JMP 00090804 
.text           C:\windows\system32\SearchIndexer.exe[2536] USER32.dll!SetWinEventHook                                                                          7767507E 5 Bytes  JMP 000901F8 
.text           C:\windows\system32\SearchIndexer.exe[2536] USER32.dll!SetWindowsHookExA                                                                        77696DFA 5 Bytes  JMP 00090600 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] ntdll.dll!LdrUnloadDll                                                                          778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] ntdll.dll!LdrLoadDll                                                                            778EF425 5 Bytes  JMP 000501F8 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] kernel32.dll!GetBinaryTypeW + 70                                                                76F978FC 1 Byte  [62]
.text           C:\windows\servicing\TrustedInstaller.exe[2708] USER32.dll!UnhookWindowsHookEx                                                                  7766CC7B 5 Bytes  JMP 000F0A08 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] USER32.dll!UnhookWinEvent                                                                       7766D924 5 Bytes  JMP 000F03FC 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] USER32.dll!SetWindowsHookExW                                                                    7767210A 5 Bytes  JMP 000F0804 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] USER32.dll!SetWinEventHook                                                                      7767507E 5 Bytes  JMP 000F01F8 
.text           C:\windows\servicing\TrustedInstaller.exe[2708] USER32.dll!SetWindowsHookExA                                                                    77696DFA 5 Bytes  JMP 000F0600 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] ntdll.dll!LdrUnloadDll                                           778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] ntdll.dll!LdrLoadDll                                             778EF425 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] kernel32.dll!GetBinaryTypeW + 70                                 76F978FC 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] USER32.dll!UnhookWindowsHookEx                                   7766CC7B 5 Bytes  JMP 00230A08 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] USER32.dll!UnhookWinEvent                                        7766D924 5 Bytes  JMP 002303FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] USER32.dll!SetWindowsHookExW                                     7767210A 5 Bytes  JMP 00230804 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] USER32.dll!SetWinEventHook                                       7767507E 5 Bytes  JMP 002301F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2728] USER32.dll!SetWindowsHookExA                                     77696DFA 5 Bytes  JMP 00230600 
.text           C:\windows\system32\svchost.exe[2768] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[2768] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[2768] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] ntdll.dll!LdrUnloadDll                                                                    778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] ntdll.dll!LdrLoadDll                                                                      778EF425 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] kernel32.dll!CreateThread                                                                 76F8279D 5 Bytes  JMP 652E75CB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] kernel32.dll!GetBinaryTypeW + 70                                                          76F978FC 1 Byte  [62]
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CreateDialogParamW                                                             77669BFF 5 Bytes  JMP 654790F0 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!EnableWindow                                                                   7766A72E 5 Bytes  JMP 65329EAC C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!GetAsyncKeyState                                                               7766C09A 5 Bytes  JMP 652CDEAD C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!UnhookWindowsHookEx                                                            7766CC7B 5 Bytes  JMP 6536ECE0 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CallNextHookEx                                                                 7766CC8F 5 Bytes  JMP 65347FDF C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!UnhookWinEvent                                                                 7766D924 5 Bytes  JMP 000F03FC 
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!DefWindowProcA                                                                 7766E0E4 7 Bytes  JMP 652E97F5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CreateWindowExA                                                                7766E18A 5 Bytes  JMP 652F362B C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CreateWindowExW                                                                77670E51 5 Bytes  JMP 653503B7 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!SetWindowsHookExW                                                              7767210A 5 Bytes  JMP 653225AC C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!GetKeyState                                                                    77674FDA 5 Bytes  JMP 652CDD87 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!SetWinEventHook                                                                7767507E 5 Bytes  JMP 000F01F8 
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!IsDialogMessageW                                                               77676F06 5 Bytes  JMP 65479855 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!DefWindowProcW                                                                 7767724B 7 Bytes  JMP 65348042 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CreateDialogParamA                                                             77683E79 5 Bytes  JMP 654790B8 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!IsDialogMessage                                                                7768407A 5 Bytes  JMP 6547982D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CreateDialogIndirectParamA                                                     77689110 5 Bytes  JMP 65479128 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!CreateDialogIndirectParamW                                                     776908AD 5 Bytes  JMP 65479160 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!DialogBoxIndirectParamW                                                        77694AA7 5 Bytes  JMP 65478D86 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!EndDialog                                                                      7769555C 5 Bytes  JMP 65479B01 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!DialogBoxParamW                                                                7769564A 5 Bytes  JMP 6528187B C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!SetKeyboardState                                                               77696B52 5 Bytes  JMP 6547A11D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!SetWindowsHookExA                                                              77696DFA 5 Bytes  JMP 000F0600 
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!SendInput                                                                      77697055 5 Bytes  JMP 6547A0C5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!SetCursorPos                                                                   776AC1D8 5 Bytes  JMP 6547A19E C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!DialogBoxParamA                                                                776ACF6A 5 Bytes  JMP 65478D21 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!DialogBoxIndirectParamA                                                        776AD29C 5 Bytes  JMP 65478DEB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!MessageBoxIndirectA                                                            776BE8C9 5 Bytes  JMP 65478CA8 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!MessageBoxIndirectW                                                            776BE9C3 5 Bytes  JMP 65478C2F C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!MessageBoxExA                                                                  776BEA29 5 Bytes  JMP 65478BCB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!MessageBoxExW                                                                  776BEA4D 5 Bytes  JMP 65478B67 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] USER32.dll!keybd_event                                                                    776BEC9B 5 Bytes  JMP 6547A082 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] SHELL32.dll!SHChangeNotification_Lock + 45BA                                              75DBB440 4 Bytes  [CF, 01, 1E, 65]
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] SHELL32.dll!SHChangeNotification_Lock + 45C2                                              75DBB448 8 Bytes  [E0, 61, 1D, 65, 79, F7, 1D, ...]
.text           C:\Program Files\Internet Explorer\iexplore.exe[2896] ole32.dll!OleLoadFromStream                                                               77735BF6 5 Bytes  JMP 6547955F C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\windows\system32\taskeng.exe[2988] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\taskeng.exe[2988] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\taskeng.exe[2988] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\taskeng.exe[2988] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00080A08 
.text           C:\windows\system32\taskeng.exe[2988] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 000803FC 
.text           C:\windows\system32\taskeng.exe[2988] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00080804 
.text           C:\windows\system32\taskeng.exe[2988] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 000801F8 
.text           C:\windows\system32\taskeng.exe[2988] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00080600 
.text           C:\windows\system32\Dwm.exe[3024] ntdll.dll!LdrUnloadDll                                                                                        778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\Dwm.exe[3024] ntdll.dll!LdrLoadDll                                                                                          778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\Dwm.exe[3024] kernel32.dll!GetBinaryTypeW + 70                                                                              76F978FC 1 Byte  [62]
.text           C:\windows\system32\Dwm.exe[3024] USER32.dll!UnhookWindowsHookEx                                                                                7766CC7B 5 Bytes  JMP 000F0A08 
.text           C:\windows\system32\Dwm.exe[3024] USER32.dll!UnhookWinEvent                                                                                     7766D924 5 Bytes  JMP 000F03FC 
.text           C:\windows\system32\Dwm.exe[3024] USER32.dll!SetWindowsHookExW                                                                                  7767210A 5 Bytes  JMP 000F0804 
.text           C:\windows\system32\Dwm.exe[3024] USER32.dll!SetWinEventHook                                                                                    7767507E 5 Bytes  JMP 000F01F8 
.text           C:\windows\system32\Dwm.exe[3024] USER32.dll!SetWindowsHookExA                                                                                  77696DFA 5 Bytes  JMP 000F0600 
.text           C:\windows\Explorer.EXE[3048] ntdll.dll!LdrUnloadDll                                                                                            778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\Explorer.EXE[3048] ntdll.dll!LdrLoadDll                                                                                              778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\Explorer.EXE[3048] kernel32.dll!GetBinaryTypeW + 70                                                                                  76F978FC 1 Byte  [62]
.text           C:\windows\Explorer.EXE[3048] USER32.dll!UnhookWindowsHookEx                                                                                    7766CC7B 5 Bytes  JMP 00110A08 
.text           C:\windows\Explorer.EXE[3048] USER32.dll!UnhookWinEvent                                                                                         7766D924 5 Bytes  JMP 001103FC 
.text           C:\windows\Explorer.EXE[3048] USER32.dll!SetWindowsHookExW                                                                                      7767210A 5 Bytes  JMP 00110804 
.text           C:\windows\Explorer.EXE[3048] USER32.dll!SetWinEventHook                                                                                        7767507E 5 Bytes  JMP 001101F8 
.text           C:\windows\Explorer.EXE[3048] USER32.dll!SetWindowsHookExA                                                                                      77696DFA 5 Bytes  JMP 00110600 
.text           C:\windows\system32\taskhost.exe[3056] ntdll.dll!LdrUnloadDll                                                                                   778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\windows\system32\taskhost.exe[3056] ntdll.dll!LdrLoadDll                                                                                     778EF425 5 Bytes  JMP 000501F8 
.text           C:\windows\system32\taskhost.exe[3056] kernel32.dll!GetBinaryTypeW + 70                                                                         76F978FC 1 Byte  [62]
.text           C:\windows\system32\taskhost.exe[3056] USER32.dll!UnhookWindowsHookEx                                                                           7766CC7B 5 Bytes  JMP 000E0A08 
.text           C:\windows\system32\taskhost.exe[3056] USER32.dll!UnhookWinEvent                                                                                7766D924 5 Bytes  JMP 000E03FC 
.text           C:\windows\system32\taskhost.exe[3056] USER32.dll!SetWindowsHookExW                                                                             7767210A 5 Bytes  JMP 000E0804 
.text           C:\windows\system32\taskhost.exe[3056] USER32.dll!SetWinEventHook                                                                               7767507E 5 Bytes  JMP 000E01F8 
.text           C:\windows\system32\taskhost.exe[3056] USER32.dll!SetWindowsHookExA                                                                             77696DFA 5 Bytes  JMP 000E0600 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] ntdll.dll!LdrUnloadDll                                                       778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] ntdll.dll!LdrLoadDll                                                         778EF425 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] kernel32.dll!GetBinaryTypeW + 70                                             76F978FC 1 Byte  [62]
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] USER32.dll!UnhookWindowsHookEx                                               7766CC7B 5 Bytes  JMP 000F0A08 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] USER32.dll!UnhookWinEvent                                                    7766D924 5 Bytes  JMP 000F03FC 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] USER32.dll!SetWindowsHookExW                                                 7767210A 5 Bytes  JMP 000F0804 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] USER32.dll!SetWinEventHook                                                   7767507E 5 Bytes  JMP 000F01F8 
.text           C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[3152] USER32.dll!SetWindowsHookExA                                                 77696DFA 5 Bytes  JMP 000F0600 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] ntdll.dll!LdrUnloadDll                                                                    778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] ntdll.dll!LdrLoadDll                                                                      778EF425 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] kernel32.dll!GetBinaryTypeW + 70                                                          76F978FC 1 Byte  [62]
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!EnableWindow                                                                   7766A72E 5 Bytes  JMP 65329EAC C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!UnhookWindowsHookEx                                                            7766CC7B 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!UnhookWinEvent                                                                 7766D924 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!SetWindowsHookExW                                                              7767210A 5 Bytes  JMP 00180804 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!SetWinEventHook                                                                7767507E 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!DialogBoxIndirectParamW                                                        77694AA7 5 Bytes  JMP 65478D86 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!DialogBoxParamW                                                                7769564A 5 Bytes  JMP 6528187B C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!SetWindowsHookExA                                                              77696DFA 5 Bytes  JMP 00180600 
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!DialogBoxParamA                                                                776ACF6A 5 Bytes  JMP 65478D21 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!DialogBoxIndirectParamA                                                        776AD29C 5 Bytes  JMP 65478DEB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!MessageBoxIndirectA                                                            776BE8C9 5 Bytes  JMP 65478CA8 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!MessageBoxIndirectW                                                            776BE9C3 5 Bytes  JMP 65478C2F C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!MessageBoxExA                                                                  776BEA29 5 Bytes  JMP 65478BCB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[3172] USER32.dll!MessageBoxExW                                                                  776BEA4D 5 Bytes  JMP 65478B67 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] ntdll.dll!LdrUnloadDll                                                         778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] ntdll.dll!LdrLoadDll                                                           778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] kernel32.dll!GetBinaryTypeW + 70                                               76F978FC 1 Byte  [62]
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] USER32.dll!UnhookWindowsHookEx                                                 7766CC7B 5 Bytes  JMP 001F0A08 
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] USER32.dll!UnhookWinEvent                                                      7766D924 5 Bytes  JMP 001F03FC 
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] USER32.dll!SetWindowsHookExW                                                   7767210A 5 Bytes  JMP 001F0804 
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] USER32.dll!SetWinEventHook                                                     7767507E 5 Bytes  JMP 001F01F8 
.text           C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[3180] USER32.dll!SetWindowsHookExA                                                   77696DFA 5 Bytes  JMP 001F0600 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] ntdll.dll!LdrUnloadDll                                                     778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] ntdll.dll!LdrLoadDll                                                       778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] kernel32.dll!GetBinaryTypeW + 70                                           76F978FC 1 Byte  [62]
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] USER32.dll!UnhookWindowsHookEx                                             7766CC7B 5 Bytes  JMP 00210A08 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] USER32.dll!UnhookWinEvent                                                  7766D924 5 Bytes  JMP 002103FC 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] USER32.dll!SetWindowsHookExW                                               7767210A 5 Bytes  JMP 00210804 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] USER32.dll!SetWinEventHook                                                 7767507E 5 Bytes  JMP 002101F8 
.text           C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3188] USER32.dll!SetWindowsHookExA                                               77696DFA 5 Bytes  JMP 00210600 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] ntdll.dll!LdrUnloadDll                                                 778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] ntdll.dll!LdrLoadDll                                                   778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] kernel32.dll!GetBinaryTypeW + 70                                       76F978FC 1 Byte  [62]
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] USER32.dll!UnhookWindowsHookEx                                         7766CC7B 5 Bytes  JMP 00190A08 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] USER32.dll!UnhookWinEvent                                              7766D924 5 Bytes  JMP 001903FC 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] USER32.dll!SetWindowsHookExW                                           7767210A 5 Bytes  JMP 00190804 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] USER32.dll!SetWinEventHook                                             7767507E 5 Bytes  JMP 001901F8 
.text           C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[3196] USER32.dll!SetWindowsHookExA                                           77696DFA 5 Bytes  JMP 00190600 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] ntdll.dll!LdrUnloadDll                                               778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] ntdll.dll!LdrLoadDll                                                 778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] kernel32.dll!GetBinaryTypeW + 70                                     76F978FC 1 Byte  [62]
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] USER32.dll!UnhookWindowsHookEx                                       7766CC7B 5 Bytes  JMP 00200A08 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] USER32.dll!UnhookWinEvent                                            7766D924 5 Bytes  JMP 002003FC 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] USER32.dll!SetWindowsHookExW                                         7767210A 5 Bytes  JMP 00200804 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] USER32.dll!SetWinEventHook                                           7767507E 5 Bytes  JMP 002001F8 
.text           C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[3204] USER32.dll!SetWindowsHookExA                                         77696DFA 5 Bytes  JMP 00200600 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] ntdll.dll!LdrUnloadDll                                                                    778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] ntdll.dll!LdrLoadDll                                                                      778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] kernel32.dll!GetBinaryTypeW + 70                                                          76F978FC 1 Byte  [62]
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] USER32.dll!UnhookWindowsHookEx                                                            7766CC7B 5 Bytes  JMP 00200A08 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] USER32.dll!UnhookWinEvent                                                                 7766D924 5 Bytes  JMP 002003FC 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] USER32.dll!SetWindowsHookExW                                                              7767210A 5 Bytes  JMP 00200804 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] USER32.dll!SetWinEventHook                                                                7767507E 5 Bytes  JMP 002001F8 
.text           C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3480] USER32.dll!SetWindowsHookExA                                                              77696DFA 5 Bytes  JMP 00200600 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] ntdll.dll!LdrUnloadDll                                                                      778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] ntdll.dll!LdrLoadDll                                                                        778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] kernel32.dll!GetBinaryTypeW + 70                                                            76F978FC 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] USER32.dll!UnhookWindowsHookEx                                                              7766CC7B 5 Bytes  JMP 001F0A08 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] USER32.dll!UnhookWinEvent                                                                   7766D924 5 Bytes  JMP 001F03FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] USER32.dll!SetWindowsHookExW                                                                7767210A 5 Bytes  JMP 001F0804 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] USER32.dll!SetWinEventHook                                                                  7767507E 5 Bytes  JMP 001F01F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3536] USER32.dll!SetWindowsHookExA                                                                77696DFA 5 Bytes  JMP 001F0600 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] ntdll.dll!LdrUnloadDll                                                                    778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] ntdll.dll!LdrLoadDll                                                                      778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] kernel32.dll!GetBinaryTypeW + 70                                                          76F978FC 1 Byte  [62]
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] USER32.dll!UnhookWindowsHookEx                                                            7766CC7B 5 Bytes  JMP 00180A08 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] USER32.dll!UnhookWinEvent                                                                 7766D924 5 Bytes  JMP 001803FC 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] USER32.dll!SetWindowsHookExW                                                              7767210A 5 Bytes  JMP 00180804 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] USER32.dll!SetWinEventHook                                                                7767507E 5 Bytes  JMP 001801F8 
.text           C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[3584] USER32.dll!SetWindowsHookExA                                                              77696DFA 5 Bytes  JMP 00180600 
.text           C:\windows\system32\svchost.exe[3756] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\windows\system32\svchost.exe[3756] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000601F8 
.text           C:\windows\system32\svchost.exe[3756] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\svchost.exe[3756] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 009D0A08 
.text           C:\windows\system32\svchost.exe[3756] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 009D03FC 
.text           C:\windows\system32\svchost.exe[3756] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 009D0804 
.text           C:\windows\system32\svchost.exe[3756] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 009D01F8 
.text           C:\windows\system32\svchost.exe[3756] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 009D0600 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] ntdll.dll!LdrUnloadDll                                                                 778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] ntdll.dll!LdrLoadDll                                                                   778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] kernel32.dll!GetBinaryTypeW + 70                                                       76F978FC 1 Byte  [62]
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] USER32.dll!UnhookWindowsHookEx                                                         7766CC7B 5 Bytes  JMP 002F0A08 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] USER32.dll!UnhookWinEvent                                                              7766D924 5 Bytes  JMP 002F03FC 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] USER32.dll!SetWindowsHookExW                                                           7767210A 5 Bytes  JMP 002F0804 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] USER32.dll!SetWinEventHook                                                             7767507E 5 Bytes  JMP 002F01F8 
.text           C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[3800] USER32.dll!SetWindowsHookExA                                                           77696DFA 5 Bytes  JMP 002F0600 
.text           C:\Program Files\Phoenix Technologies Ltd\FailSafe\FailSafeLauncher.exe[3940] KERNEL32.dll!GetBinaryTypeW + 70                                  76F978FC 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] ntdll.dll!LdrUnloadDll                                                                   778EBD1F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] ntdll.dll!LdrLoadDll                                                                     778EF425 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] kernel32.dll!GetBinaryTypeW + 70                                                         76F978FC 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] USER32.dll!UnhookWindowsHookEx                                                           7766CC7B 5 Bytes  JMP 001F0A08 
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] USER32.dll!UnhookWinEvent                                                                7766D924 5 Bytes  JMP 001F03FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] USER32.dll!SetWindowsHookExW                                                             7767210A 5 Bytes  JMP 001F0804 
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] USER32.dll!SetWinEventHook                                                               7767507E 5 Bytes  JMP 001F01F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3956] USER32.dll!SetWindowsHookExA                                                             77696DFA 5 Bytes  JMP 001F0600 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] ntdll.dll!LdrUnloadDll                                                                  778EBD1F 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] ntdll.dll!LdrLoadDll                                                                    778EF425 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] kernel32.dll!GetBinaryTypeW + 70                                                        76F978FC 1 Byte  [62]
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] USER32.dll!UnhookWindowsHookEx                                                          7766CC7B 5 Bytes  JMP 00200A08 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] USER32.dll!UnhookWinEvent                                                               7766D924 5 Bytes  JMP 002003FC 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] USER32.dll!SetWindowsHookExW                                                            7767210A 5 Bytes  JMP 00200804 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] USER32.dll!SetWinEventHook                                                              7767507E 5 Bytes  JMP 002001F8 
.text           C:\Program Files\Java\jre1.5.0_17\bin\jusched.exe[3992] USER32.dll!SetWindowsHookExA                                                            77696DFA 5 Bytes  JMP 00200600 
.text           C:\Program Files\Winamp\winampa.exe[4000] ntdll.dll!LdrUnloadDll                                                                                778EBD1F 5 Bytes  JMP 000A03FC 
.text           C:\Program Files\Winamp\winampa.exe[4000] ntdll.dll!LdrLoadDll                                                                                  778EF425 5 Bytes  JMP 000A01F8 
.text           C:\Program Files\Winamp\winampa.exe[4000] kernel32.dll!GetBinaryTypeW + 70                                                                      76F978FC 1 Byte  [62]
.text           C:\Program Files\Winamp\winampa.exe[4000] USER32.dll!UnhookWindowsHookEx                                                                        7766CC7B 5 Bytes  JMP 00240A08 
.text           C:\Program Files\Winamp\winampa.exe[4000] USER32.dll!UnhookWinEvent                                                                             7766D924 5 Bytes  JMP 002403FC 
.text           C:\Program Files\Winamp\winampa.exe[4000] USER32.dll!SetWindowsHookExW                                                                          7767210A 5 Bytes  JMP 00240804 
.text           C:\Program Files\Winamp\winampa.exe[4000] USER32.dll!SetWinEventHook                                                                            7767507E 5 Bytes  JMP 002401F8 
.text           C:\Program Files\Winamp\winampa.exe[4000] USER32.dll!SetWindowsHookExA                                                                          77696DFA 5 Bytes  JMP 00240600 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] ntdll.dll!LdrUnloadDll                                                                           778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] ntdll.dll!LdrLoadDll                                                                             778EF425 5 Bytes  JMP 000601F8 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] kernel32.dll!GetBinaryTypeW + 70                                                                 76F978FC 1 Byte  [62]
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] USER32.dll!UnhookWindowsHookEx                                                                   7766CC7B 5 Bytes  JMP 000F0A08 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] USER32.dll!UnhookWinEvent                                                                        7766D924 5 Bytes  JMP 000F03FC 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] USER32.dll!SetWindowsHookExW                                                                     7767210A 5 Bytes  JMP 000F0804 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] USER32.dll!SetWinEventHook                                                                       7767507E 5 Bytes  JMP 000F01F8 
.text           C:\Program Files\iTunes\iTunesHelper.exe[4028] USER32.dll!SetWindowsHookExA                                                                     77696DFA 5 Bytes  JMP 000F0600 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] ntdll.dll!LdrUnloadDll                                                        778EBD1F 5 Bytes  JMP 000703FC 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] ntdll.dll!LdrLoadDll                                                          778EF425 5 Bytes  JMP 000701F8 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] kernel32.dll!GetBinaryTypeW + 70                                              76F978FC 1 Byte  [62]
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] USER32.dll!UnhookWindowsHookEx                                                7766CC7B 5 Bytes  JMP 00550A08 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] USER32.dll!UnhookWinEvent                                                     7766D924 5 Bytes  JMP 005503FC 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] USER32.dll!SetWindowsHookExW                                                  7767210A 5 Bytes  JMP 00550804 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] USER32.dll!SetWinEventHook                                                    7767507E 5 Bytes  JMP 005501F8 
.text           C:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe[4344] USER32.dll!SetWindowsHookExA                                                  77696DFA 5 Bytes  JMP 00550600 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] ntdll.dll!LdrUnloadDll                                                                 778EBD1F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] ntdll.dll!LdrLoadDll                                                                   778EF425 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] kernel32.dll!GetBinaryTypeW + 70                                                       76F978FC 1 Byte  [62]
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] USER32.dll!UnhookWindowsHookEx                                                         7766CC7B 5 Bytes  JMP 00100A08 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] USER32.dll!UnhookWinEvent                                                              7766D924 5 Bytes  JMP 001003FC 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] USER32.dll!SetWindowsHookExW                                                           7767210A 5 Bytes  JMP 00100804 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] USER32.dll!SetWinEventHook                                                             7767507E 5 Bytes  JMP 001001F8 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[5176] USER32.dll!SetWindowsHookExA                                                           77696DFA 5 Bytes  JMP 00100600 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] ntdll.dll!LdrUnloadDll                                                                              778EBD1F 5 Bytes  JMP 000B03FC 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] ntdll.dll!LdrLoadDll                                                                                778EF425 5 Bytes  JMP 000B01F8 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] kernel32.dll!GetBinaryTypeW + 70                                                                    76F978FC 1 Byte  [62]
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] USER32.dll!UnhookWindowsHookEx                                                                      7766CC7B 5 Bytes  JMP 00150A08 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] USER32.dll!UnhookWinEvent                                                                           7766D924 5 Bytes  JMP 001503FC 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] USER32.dll!SetWindowsHookExW                                                                        7767210A 5 Bytes  JMP 00150804 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] USER32.dll!SetWinEventHook                                                                          7767507E 5 Bytes  JMP 001501F8 
.text           C:\windows\system32\wbem\wmiprvse.exe[5384] USER32.dll!SetWindowsHookExA                                                                        77696DFA 5 Bytes  JMP 00150600 
.text           C:\windows\system32\wuauclt.exe[5668] ntdll.dll!LdrUnloadDll                                                                                    778EBD1F 5 Bytes  JMP 000703FC 
.text           C:\windows\system32\wuauclt.exe[5668] ntdll.dll!LdrLoadDll                                                                                      778EF425 5 Bytes  JMP 000701F8 
.text           C:\windows\system32\wuauclt.exe[5668] kernel32.dll!GetBinaryTypeW + 70                                                                          76F978FC 1 Byte  [62]
.text           C:\windows\system32\wuauclt.exe[5668] USER32.dll!UnhookWindowsHookEx                                                                            7766CC7B 5 Bytes  JMP 00100A08 
.text           C:\windows\system32\wuauclt.exe[5668] USER32.dll!UnhookWinEvent                                                                                 7766D924 5 Bytes  JMP 001003FC 
.text           C:\windows\system32\wuauclt.exe[5668] USER32.dll!SetWindowsHookExW                                                                              7767210A 5 Bytes  JMP 00100804 
.text           C:\windows\system32\wuauclt.exe[5668] USER32.dll!SetWinEventHook                                                                                7767507E 5 Bytes  JMP 001001F8 
.text           C:\windows\system32\wuauclt.exe[5668] USER32.dll!SetWindowsHookExA                                                                              77696DFA 5 Bytes  JMP 00100600 
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] ntdll.dll!LdrUnloadDll                                                                    778EBD1F 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] ntdll.dll!LdrLoadDll                                                                      778EF425 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] kernel32.dll!CreateThread                                                                 76F8279D 5 Bytes  JMP 652E75CB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] kernel32.dll!GetBinaryTypeW + 70                                                          76F978FC 1 Byte  [62]
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CreateDialogParamW                                                             77669BFF 5 Bytes  JMP 654790F0 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!EnableWindow                                                                   7766A72E 5 Bytes  JMP 65329EAC C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!GetAsyncKeyState                                                               7766C09A 5 Bytes  JMP 652CDEAD C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!UnhookWindowsHookEx                                                            7766CC7B 5 Bytes  JMP 6536ECE0 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CallNextHookEx                                                                 7766CC8F 5 Bytes  JMP 65347FDF C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!UnhookWinEvent                                                                 7766D924 5 Bytes  JMP 001F03FC 
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!DefWindowProcA                                                                 7766E0E4 7 Bytes  JMP 652E97F5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CreateWindowExA                                                                7766E18A 5 Bytes  JMP 652F362B C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CreateWindowExW                                                                77670E51 5 Bytes  JMP 653503B7 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!SetWindowsHookExW                                                              7767210A 5 Bytes  JMP 653225AC C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!GetKeyState                                                                    77674FDA 5 Bytes  JMP 652CDD87 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!SetWinEventHook                                                                7767507E 5 Bytes  JMP 001F01F8 
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!IsDialogMessageW                                                               77676F06 5 Bytes  JMP 65479855 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!DefWindowProcW                                                                 7767724B 7 Bytes  JMP 65348042 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CreateDialogParamA                                                             77683E79 5 Bytes  JMP 654790B8 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!IsDialogMessage                                                                7768407A 5 Bytes  JMP 6547982D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CreateDialogIndirectParamA                                                     77689110 5 Bytes  JMP 65479128 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!CreateDialogIndirectParamW                                                     776908AD 5 Bytes  JMP 65479160 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!DialogBoxIndirectParamW                                                        77694AA7 5 Bytes  JMP 65478D86 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!EndDialog                                                                      7769555C 5 Bytes  JMP 65479B01 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!DialogBoxParamW                                                                7769564A 5 Bytes  JMP 6528187B C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!SetKeyboardState                                                               77696B52 5 Bytes  JMP 6547A11D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!SetWindowsHookExA                                                              77696DFA 5 Bytes  JMP 001F0600 
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!SendInput                                                                      77697055 5 Bytes  JMP 6547A0C5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!SetCursorPos                                                                   776AC1D8 5 Bytes  JMP 6547A19E C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!DialogBoxParamA                                                                776ACF6A 5 Bytes  JMP 65478D21 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!DialogBoxIndirectParamA                                                        776AD29C 5 Bytes  JMP 65478DEB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!MessageBoxIndirectA                                                            776BE8C9 5 Bytes  JMP 65478CA8 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!MessageBoxIndirectW                                                            776BE9C3 5 Bytes  JMP 65478C2F C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!MessageBoxExA                                                                  776BEA29 5 Bytes  JMP 65478BCB C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!MessageBoxExW                                                                  776BEA4D 5 Bytes  JMP 65478B67 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] USER32.dll!keybd_event                                                                    776BEC9B 5 Bytes  JMP 6547A082 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] SHELL32.dll!SHChangeNotification_Lock + 45BA                                              75DBB440 4 Bytes  [CF, 01, 1E, 65]
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] SHELL32.dll!SHChangeNotification_Lock + 45C2                                              75DBB448 8 Bytes  [E0, 61, 1D, 65, 79, F7, 1D, ...]
.text           C:\Program Files\Internet Explorer\iexplore.exe[5748] ole32.dll!OleLoadFromStream                                                               77735BF6 5 Bytes  JMP 6547955F C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]                          [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!SearchPathW]                               [651E029E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                            [651D5EC7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW]                            [651E7F4F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW]                      [651EF500] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!FindClose]                                 [651EF94D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW]                             [651F07CA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW]                            [651EFCF6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA]                            [651D5E4F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW]                  [651EABDB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                            [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                              [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CreateFileW]                               [651D63E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW]                [651EB56B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                             [651D5EC7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                               [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW]                                  [651EBC51] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW]                                [651EC811] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW]                                [651E029E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                               [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                             [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW]                                [651D63E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                             [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW]                              [651EC811] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW]                             [651EE457] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA]                 [651EAA37] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW]                 [651EABDB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW]               [651EB56B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                             [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                           [651D5EC7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW]                           [651EFCF6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW]                            [651F07CA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW]                       [651E939B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW]                              [651D63E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW]                              [651E029E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW]                       [651D5F62] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA]                       [651E9229] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA]                              [651DF1F1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA]                           [651D5E4F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA]                       [651E0ADF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA]                              [651EF2BD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose]                                [651EF94D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA]                            [651F072B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA]                           [651EF9A0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootA]                               [651F1542] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripToRootW]                          [651F1C5E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsURLW]                                [651DFA79] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathFindOnPathW]                           [651F1191] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHCreateStreamOnFileW]                     [651DF725] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHOpenRegStream2W]                         [651DFB25] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathCombineW]                              [651F1095] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyA]                              [651F1F32] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryW]                          [651F12D2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringByKeyW]                    [651F0DFB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathCreateFromUrlW]                        [651E0178] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathSkipRootW]                             [651F1B2E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathRelativePathToW]                       [651F194A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathRemoveArgsW]                           [651F19EE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsContentTypeW]                        [651F1233] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegQueryUSValueW]                        [651DF86E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegEnumUSKeyW]                           [651DF472] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegOpenUSKeyA]                           [651F27C3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryEmptyW]                     [651F136E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryA]                          [651F1284] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootA]                            [651F0F4E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetPathW]                             [651F2769] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathCanonicalizeW]                         [651DF9DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegSetPathW]                             [651F2937] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetUSValueW]                          [651D7430] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryKeyW]                            [651DF817] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetBoolUSValueW]                      [651DE265] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRelativeW]                           [651D5D08] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsNetworkPathW]                        [651F140A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootW]                               [651F1590] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyW]                              [651F1F83] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathFileExistsW]                           [651E0123] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumValueW]                              [651F218A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripPathW]                            [651F1BC6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegOpenUSKeyW]                           [651DFACB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHQueryValueExW]                           [651DFC0B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHSetValueW]                               [651F2B62] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteValueW]                            [651F2028] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootW]                            [651F0F9F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHGetValueW]                               [651D4927] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringW]                         [651F0D47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCW]                                [651DFA2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathMakeSystemFolderW]                     [651F18A2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathUnExpandEnvStringsW]                   [651F1CAC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerW]                          [651F171C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerShareW]                     [651F17B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetValueW]                            [651D4984] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumKeyExW]                              [651F20D3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile]                        [651E8C1A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [USER32.dll!LoadImageW]                                 [651ECB0F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [USER32.dll!WinHelpW]                                   [651ED6BF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW]                       [651ED11F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                             [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW]                          [651EC49D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW]               [651EB56B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW]              [651EB245] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW]           [651EA89F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW]                              [651EE0C1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                             [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW]                 [651EABDB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW]                    [651EA249] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA]                        [651E9AF3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW]                             [651EE457] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW]                                [651EE089] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW]                           [651E9F4B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW]                                [651EBC51] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW]                [651EA56D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                               [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                               [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA]                   [651DF6D1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA]                              [651F1F32] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW]                            [651F2028] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA]                               [651F2B05] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW]                               [651F2B62] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW]                        [651E0178] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetUSValueA]                          [651D64C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA]                               [651D4CAA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW]                               [651D4927] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW]                            [651D4984] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA]                            [651D6528] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[2896] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                 [73C824FA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                            [73C6565B] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                           [73C65719] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                  [73C82575] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                        [73C785D9] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                          [73C74D8D] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                         [73C75134] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                        [73C75209] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP]                                               [73C76736] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                         [73C78330] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                    [73C7887F] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                  [73C790E0] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                        [73C7E283] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\windows\Explorer.EXE[3048] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                            [73C74CBF] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.17007_none_72f44f3186198a88\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Program Files\Phoenix Technologies Ltd\FailSafe\FailSafeLauncher.exe[3940] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]    [75975E25] C:\windows\system32\apphelp.dll (Biblioteka klienta zgodności aplikacji/Microsoft Corporation)
IAT             C:\Program Files\Phoenix Technologies Ltd\FailSafe\FailSafeLauncher.exe[3940] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]     [75975E25] C:\windows\system32\apphelp.dll (Biblioteka klienta zgodności aplikacji/Microsoft Corporation)
IAT             C:\Program Files\Phoenix Technologies Ltd\FailSafe\FailSafeLauncher.exe[3940] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]   [75975E25] C:\windows\system32\apphelp.dll (Biblioteka klienta zgodności aplikacji/Microsoft Corporation)
IAT             C:\Program Files\Phoenix Technologies Ltd\FailSafe\FailSafeLauncher.exe[3940] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]  [75975E25] C:\windows\system32\apphelp.dll (Biblioteka klienta zgodności aplikacji/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]                          [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!SearchPathW]                               [651E029E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                            [651D5EC7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW]                            [651E7F4F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW]                      [651EF500] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!FindClose]                                 [651EF94D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW]                             [651F07CA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW]                            [651EFCF6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA]                            [651D5E4F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW]                  [651EABDB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                            [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                              [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CreateFileW]                               [651D63E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW]                [651EB56B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                             [651D5EC7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                               [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW]                                  [651EBC51] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW]                                [651EC811] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW]                                [651E029E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                               [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                             [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW]                                [651D63E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                             [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW]                              [651EC811] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW]                             [651EE457] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA]                 [651EAA37] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW]                 [651EABDB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW]               [651EB56B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                             [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                           [651D5EC7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW]                           [651EFCF6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW]                            [651F07CA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW]                       [651E939B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW]                              [651D63E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW]                              [651E029E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW]                       [651D5F62] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA]                       [651E9229] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA]                              [651DF1F1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA]                           [651D5E4F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA]                       [651E0ADF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA]                              [651EF2BD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose]                                [651EF94D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA]                            [651F072B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA]                           [651EF9A0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootA]                               [651F1542] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripToRootW]                          [651F1C5E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsURLW]                                [651DFA79] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathFindOnPathW]                           [651F1191] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHCreateStreamOnFileW]                     [651DF725] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHOpenRegStream2W]                         [651DFB25] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathCombineW]                              [651F1095] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyA]                              [651F1F32] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryW]                          [651F12D2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringByKeyW]                    [651F0DFB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathCreateFromUrlW]                        [651E0178] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathSkipRootW]                             [651F1B2E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathRelativePathToW]                       [651F194A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathRemoveArgsW]                           [651F19EE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsContentTypeW]                        [651F1233] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegQueryUSValueW]                        [651DF86E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegEnumUSKeyW]                           [651DF472] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegOpenUSKeyA]                           [651F27C3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryEmptyW]                     [651F136E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryA]                          [651F1284] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootA]                            [651F0F4E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetPathW]                             [651F2769] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathCanonicalizeW]                         [651DF9DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegSetPathW]                             [651F2937] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetUSValueW]                          [651D7430] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryKeyW]                            [651DF817] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetBoolUSValueW]                      [651DE265] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRelativeW]                           [651D5D08] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsNetworkPathW]                        [651F140A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootW]                               [651F1590] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyW]                              [651F1F83] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathFileExistsW]                           [651E0123] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumValueW]                              [651F218A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripPathW]                            [651F1BC6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegOpenUSKeyW]                           [651DFACB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHQueryValueExW]                           [651DFC0B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHSetValueW]                               [651F2B62] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteValueW]                            [651F2028] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootW]                            [651F0F9F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHGetValueW]                               [651D4927] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringW]                         [651F0D47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCW]                                [651DFA2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathMakeSystemFolderW]                     [651F18A2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathUnExpandEnvStringsW]                   [651F1CAC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerW]                          [651F171C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerShareW]                     [651F17B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetValueW]                            [651D4984] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumKeyExW]                              [651F20D3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile]                        [651E8C1A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [USER32.dll!LoadImageW]                                 [651ECB0F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [USER32.dll!WinHelpW]                                   [651ED6BF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW]                       [651ED11F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                             [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW]                          [651EC49D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW]               [651EB56B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW]              [651EB245] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW]           [651EA89F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW]                              [651EE0C1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                             [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW]                 [651EABDB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW]                    [651EA249] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA]                        [651E9AF3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW]                             [651EE457] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW]                                [651EE089] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW]                           [651E9F4B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW]                                [651EBC51] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW]                [651EA56D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                               [651D4E2B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                               [651D6D22] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA]                   [651DF6D1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA]                              [651F1F32] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW]                            [651F2028] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA]                               [651F2B05] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW]                               [651F2B62] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW]                        [651E0178] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetUSValueA]                          [651D64C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA]                               [651D4CAA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW]                               [651D4927] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW]                            [651D4984] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA]                            [651D6528] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT             C:\Program Files\Internet Explorer\iexplore.exe[5748] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress]                           [651D47BB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                                                                         Wdf01000.sys (Aparat wykonawczy struktury sterowników trybu jądra/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                                                                         Wdf01000.sys (Aparat wykonawczy struktury sterowników trybu jądra/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                         aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                                          fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                                          fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                                          fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                                                          fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device          \Driver\ACPI_HAL \Device\0000004c                                                                                                               halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                         aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device          \Driver\BTHUSB \Device\0000007c                                                                                                                 bthport.sys (Sterownik magistrali Bluetooth/Microsoft Corporation)

---- Threads - GMER 1.0.15 ----

Thread          System [4:5352]                                                                                                                                 A39A0F2E

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0026b654edff                                                                     
Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0026b654f652                                                                     
Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0026b66b6864                                                                     
Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0026b66b6982                                                                     
Reg             HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\b482fe3967c9                                                                     
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                             0x00 0x00 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                             0
Reg             HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                          0xD1 0xA7 0x30 0xE1 ...
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0026b654edff (not active ControlSet)                                                 
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0026b654f652 (not active ControlSet)                                                 
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0026b66b6864 (not active ControlSet)                                                 
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0026b66b6982 (not active ControlSet)                                                 
Reg             HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\b482fe3967c9 (not active ControlSet)                                                 
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                            
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                 0x00 0x00 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                 0
Reg             HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                              0xD1 0xA7 0x30 0xE1 ...

---- EOF - GMER 1.0.15 ----
