GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-11-07 20:09:33
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK1032GSX rev.AS022M
Running: ivilkeh3.exe; Driver: C:\Users\Rumianek\AppData\Local\Temp\kgrdikod.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwAddBootEntry [0x8DD3A4BA]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwAllocateVirtualMemory [0x8DFA8C22]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwAssignProcessToJobObject [0x8DD3AED6]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateEvent [0x8DD45FA8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateEventPair [0x8DD45FF4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateIoCompletion [0x8DD46176]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateMutant [0x8DD45F16]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwCreateSection [0x8DFA8FA6]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateSemaphore [0x8DD45F5E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateThread [0x8DD3B11C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateTimer [0x8DD46130]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwDebugActiveProcess [0x8DD3B93E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwDeleteBootEntry [0x8DD3A508]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwFreeVirtualMemory [0x8DFA8CEA]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwLoadDriver [0x8DFA73EC]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwModifyBootEntry [0x8DD3A556]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwNotifyChangeKey [0x8DD3F534]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwNotifyChangeMultipleKeys [0x8DD3C3A6]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenEvent [0x8DD45FD2]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenEventPair [0x8DD46016]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenIoCompletion [0x8DD4619A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenMutant [0x8DD45F3C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenSection [0x8DD460BA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenSemaphore [0x8DD45F86]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwOpenTimer [0x8DD46154]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwProtectVirtualMemory [0x8DFA8E4A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwQueryObject [0x8DD3C272]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwQueueApcThread [0x8DD3BDD4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSetBootEntryOrder [0x8DD3A5A4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSetBootOptions [0x8DD3A5F2]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSetContextThread [0x8DD3B7BE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSetSystemInformation [0x8DD3A1FA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSetSystemPowerState [0x8DD3A3AA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwShutdownSystem [0x8DD3A350]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSuspendProcess [0x8DD3BAF8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSuspendThread [0x8DD3BC54]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwSystemDebugControl [0x8DD3A41A]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwTerminateProcess [0x8DFA8EFE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwTerminateThread [0x8DD3B636]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwUnloadDriver [0x8DFA741C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwVdmControl [0x8DD3A640]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwWriteVirtualMemory [0x8DFA8D96]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                ZwCreateThreadEx [0x8DD3B2F4]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ZwCreateProcessEx [0x8DFC1E56]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text           ntoskrnl.exe!KeInsertQueue + 2FD                                                                                                                     828A6934 4 Bytes  [BA, A4, D3, 8D]
.text           ntoskrnl.exe!KeInsertQueue + 321                                                                                                                     828A6958 4 Bytes  [22, 8C, FA, 8D]
.text           ntoskrnl.exe!KeInsertQueue + 381                                                                                                                     828A69B8 4 Bytes  [D6, AE, D3, 8D]
.text           ntoskrnl.exe!KeInsertQueue + 3C1                                                                                                                     828A69F8 8 Bytes  [A8, 5F, D4, 8D, F4, 5F, D4, ...] {TEST AL, 0x5f; AAM 0x8d; HLT ; POP EDI; AAM 0x8d}
.text           ntoskrnl.exe!KeInsertQueue + 3CD                                                                                                                     828A6A04 4 Bytes  [76, 61, D4, 8D] {JBE 0x63; AAM 0x8d}
.text           ...                                                                                                                                                  
PAGE            ntoskrnl.exe!ObMakeTemporaryObject                                                                                                                   829DCE46 5 Bytes  JMP 8DFBECF6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntoskrnl.exe!ZwReplyWaitReceivePortEx + 110                                                                                                          82A2654F 4 Bytes  CALL 8DD3CA8D \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            ntoskrnl.exe!ObInsertObject                                                                                                                          82A2AA1C 5 Bytes  JMP 8DFC0810 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntoskrnl.exe!ZwAlpcSendWaitReceivePort + 121                                                                                                         82A54017 4 Bytes  CALL 8DD3CAA3 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            ntoskrnl.exe!ZwCreateProcessEx                                                                                                                       82AC1EC6 7 Bytes  JMP 8DFC1E5A \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text           ntdll.dll!LdrLoadDll                                                                                                                                 77D59378 5 Bytes  [E9, 7B, 6E, 40, 88] {JMP 0xffffffff88406e80}
.text           ntdll.dll!LdrUnloadDll                                                                                                                               77D6B680 5 Bytes  [E9, 77, 4D, 3F, 88] {JMP 0xffffffff883f4d7c}

---- User code sections - GMER 1.0.15 ----

.text           C:\Windows\system32\svchost.exe[196] kernel32.dll!GetBinaryTypeW + 70                                                                                774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ntdll.dll!LdrLoadDll                                                                 77D59378 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ntdll.dll!LdrUnloadDll                                                               77D6B680 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] KERNEL32.dll!GetBinaryTypeW + 70                                                     774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] USER32.dll!SetWindowsHookExA                                                         77636322 5 Bytes  JMP 00190600 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] USER32.dll!SetWindowsHookExW                                                         776387AD 5 Bytes  JMP 00190804 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] USER32.dll!UnhookWindowsHookEx                                                       776398DB 5 Bytes  JMP 00190A08 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] USER32.dll!SetWinEventHook                                                           77639F3A 5 Bytes  JMP 001901F8 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] USER32.dll!UnhookWinEvent                                                            7763C06F 5 Bytes  JMP 001903FC 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!CreateServiceW                                                          76419EB4 5 Bytes  JMP 001A03FC 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!DeleteService                                                           7641A07E 5 Bytes  JMP 001A0600 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!SetServiceObjectSecurity                                                76456CD9 5 Bytes  JMP 001A1014 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!ChangeServiceConfigA                                                    76456DD9 5 Bytes  JMP 001A0804 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!ChangeServiceConfigW                                                    76456F81 5 Bytes  JMP 001A0A08 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!ChangeServiceConfig2A                                                   76457099 5 Bytes  JMP 001A0C0C 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!ChangeServiceConfig2W                                                   764571E1 5 Bytes  JMP 001A0E10 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] ADVAPI32.dll!CreateServiceA                                                          764572A1 5 Bytes  JMP 001A01F8 
.text           C:\Windows\system32\taskeng.exe[292] kernel32.dll!GetBinaryTypeW + 70                                                                                774F2247 1 Byte  [62]
.text           C:\Windows\system32\taskeng.exe[320] kernel32.dll!GetBinaryTypeW + 70                                                                                774F2247 1 Byte  [62]
.text           C:\Windows\system32\csrss.exe[608] KERNEL32.dll!GetBinaryTypeW + 70                                                                                  774F2247 1 Byte  [62]
.text           C:\Windows\system32\wininit.exe[652] kernel32.dll!GetBinaryTypeW + 70                                                                                774F2247 1 Byte  [62]
.text           C:\Windows\system32\csrss.exe[664] KERNEL32.dll!GetBinaryTypeW + 70                                                                                  774F2247 1 Byte  [62]
.text           ...                                                                                                                                                  
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ntdll.dll!LdrLoadDll                                                                            77D59378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ntdll.dll!LdrUnloadDll                                                                          77D6B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] KERNEL32.dll!GetBinaryTypeW + 70                                                                774F2247 1 Byte  [62]
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!CreateServiceW                                                                     76419EB4 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!DeleteService                                                                      7641A07E 5 Bytes  JMP 00160600 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!SetServiceObjectSecurity                                                           76456CD9 5 Bytes  JMP 00161014 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!ChangeServiceConfigA                                                               76456DD9 5 Bytes  JMP 00160804 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!ChangeServiceConfigW                                                               76456F81 5 Bytes  JMP 00160A08 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!ChangeServiceConfig2A                                                              76457099 5 Bytes  JMP 00160C0C 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!ChangeServiceConfig2W                                                              764571E1 5 Bytes  JMP 00160E10 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] ADVAPI32.dll!CreateServiceA                                                                     764572A1 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] USER32.dll!SetWindowsHookExA                                                                    77636322 5 Bytes  JMP 00180600 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] USER32.dll!SetWindowsHookExW                                                                    776387AD 5 Bytes  JMP 00180804 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] USER32.dll!UnhookWindowsHookEx                                                                  776398DB 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] USER32.dll!SetWinEventHook                                                                      77639F3A 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[976] USER32.dll!UnhookWinEvent                                                                       7763C06F 5 Bytes  JMP 001803FC 
.text           C:\Windows\system32\svchost.exe[1024] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[1156] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[1184] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1220] kernel32.dll!GetBinaryTypeW + 70                                                    774F2247 1 Byte  [62]
.text           ...                                                                                                                                                  
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ntdll.dll!LdrLoadDll                                                              77D59378 5 Bytes  JMP 001701F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ntdll.dll!LdrUnloadDll                                                            77D6B680 5 Bytes  JMP 001703FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] KERNEL32.dll!GetBinaryTypeW + 70                                                  774F2247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] USER32.dll!SetWindowsHookExA                                                      77636322 5 Bytes  JMP 00210600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] USER32.dll!SetWindowsHookExW                                                      776387AD 5 Bytes  JMP 00210804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] USER32.dll!UnhookWindowsHookEx                                                    776398DB 5 Bytes  JMP 00210A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] USER32.dll!SetWinEventHook                                                        77639F3A 5 Bytes  JMP 002101F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] USER32.dll!UnhookWinEvent                                                         7763C06F 5 Bytes  JMP 002103FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!CreateServiceW                                                       76419EB4 5 Bytes  JMP 002203FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!DeleteService                                                        7641A07E 5 Bytes  JMP 00220600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!SetServiceObjectSecurity                                             76456CD9 5 Bytes  JMP 00221014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!ChangeServiceConfigA                                                 76456DD9 5 Bytes  JMP 00220804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!ChangeServiceConfigW                                                 76456F81 5 Bytes  JMP 00220A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!ChangeServiceConfig2A                                                76457099 5 Bytes  JMP 00220C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!ChangeServiceConfig2W                                                764571E1 5 Bytes  JMP 00220E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] ADVAPI32.dll!CreateServiceA                                                       764572A1 5 Bytes  JMP 002201F8 
.text           C:\Windows\System32\hkcmd.exe[1304] ntdll.dll!LdrLoadDll                                                                                             77D59378 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\hkcmd.exe[1304] ntdll.dll!LdrUnloadDll                                                                                           77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Windows\System32\hkcmd.exe[1304] KERNEL32.dll!GetBinaryTypeW + 70                                                                                 774F2247 1 Byte  [62]
.text           C:\Windows\System32\hkcmd.exe[1304] USER32.dll!SetWindowsHookExA                                                                                     77636322 5 Bytes  JMP 00170600 
.text           C:\Windows\System32\hkcmd.exe[1304] USER32.dll!SetWindowsHookExW                                                                                     776387AD 5 Bytes  JMP 00170804 
.text           C:\Windows\System32\hkcmd.exe[1304] USER32.dll!UnhookWindowsHookEx                                                                                   776398DB 5 Bytes  JMP 00170A08 
.text           C:\Windows\System32\hkcmd.exe[1304] USER32.dll!SetWinEventHook                                                                                       77639F3A 5 Bytes  JMP 001701F8 
.text           C:\Windows\System32\hkcmd.exe[1304] USER32.dll!UnhookWinEvent                                                                                        7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!CreateServiceW                                                                                      76419EB4 5 Bytes  JMP 001803FC 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!DeleteService                                                                                       7641A07E 5 Bytes  JMP 00180600 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!SetServiceObjectSecurity                                                                            76456CD9 5 Bytes  JMP 00181014 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!ChangeServiceConfigA                                                                                76456DD9 5 Bytes  JMP 00180804 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!ChangeServiceConfigW                                                                                76456F81 5 Bytes  JMP 00180A08 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!ChangeServiceConfig2A                                                                               76457099 5 Bytes  JMP 00180C0C 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!ChangeServiceConfig2W                                                                               764571E1 5 Bytes  JMP 00180E10 
.text           C:\Windows\System32\hkcmd.exe[1304] ADVAPI32.dll!CreateServiceA                                                                                      764572A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\system32\AUDIODG.EXE[1360] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1388] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1428] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1628] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1820] kernel32.dll!SetUnhandledExceptionFilter                                                   774CA84F 4 Bytes  [C2, 04, 00, 90] {RET 0x4; NOP }
.text           C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1820] kernel32.dll!GetBinaryTypeW + 70                                                           774F2247 1 Byte  [62]
.text           C:\Windows\system32\Dwm.exe[1912] kernel32.dll!GetBinaryTypeW + 70                                                                                   774F2247 1 Byte  [62]
.text           C:\Windows\Explorer.EXE[1968] kernel32.dll!GetBinaryTypeW + 70                                                                                       774F2247 1 Byte  [62]
.text           C:\Windows\Explorer.EXE[1968] SHELL32.dll!SHFileOperationW                                                                                           768968E8 5 Bytes  JMP 10001102 C:\Program Files\Unlocker\UnlockerHook.dll
.text           C:\Windows\System32\spoolsv.exe[2036] kernel32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ntdll.dll!LdrLoadDll                                                                    77D59378 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ntdll.dll!LdrUnloadDll                                                                  77D6B680 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] KERNEL32.dll!GetBinaryTypeW + 70                                                        774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] USER32.dll!SetWindowsHookExA                                                            77636322 5 Bytes  JMP 00080600 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] USER32.dll!SetWindowsHookExW                                                            776387AD 5 Bytes  JMP 00080804 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] USER32.dll!UnhookWindowsHookEx                                                          776398DB 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] USER32.dll!SetWinEventHook                                                              77639F3A 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] USER32.dll!UnhookWinEvent                                                               7763C06F 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!CreateServiceW                                                             76419EB4 5 Bytes  JMP 000903FC 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!DeleteService                                                              7641A07E 5 Bytes  JMP 00090600 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!SetServiceObjectSecurity                                                   76456CD9 5 Bytes  JMP 00091014 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!ChangeServiceConfigA                                                       76456DD9 5 Bytes  JMP 00090804 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!ChangeServiceConfigW                                                       76456F81 5 Bytes  JMP 00090A08 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!ChangeServiceConfig2A                                                      76457099 5 Bytes  JMP 00090C0C 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!ChangeServiceConfig2W                                                      764571E1 5 Bytes  JMP 00090E10 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2180] ADVAPI32.dll!CreateServiceA                                                             764572A1 5 Bytes  JMP 000901F8 
.text           C:\Windows\System32\igfxpers.exe[2252] ntdll.dll!LdrLoadDll                                                                                          77D59378 5 Bytes  JMP 001501F8 
.text           C:\Windows\System32\igfxpers.exe[2252] ntdll.dll!LdrUnloadDll                                                                                        77D6B680 5 Bytes  JMP 001503FC 
.text           C:\Windows\System32\igfxpers.exe[2252] KERNEL32.dll!GetBinaryTypeW + 70                                                                              774F2247 1 Byte  [62]
.text           C:\Windows\System32\igfxpers.exe[2252] USER32.dll!SetWindowsHookExA                                                                                  77636322 5 Bytes  JMP 00160600 
.text           C:\Windows\System32\igfxpers.exe[2252] USER32.dll!SetWindowsHookExW                                                                                  776387AD 5 Bytes  JMP 00160804 
.text           C:\Windows\System32\igfxpers.exe[2252] USER32.dll!UnhookWindowsHookEx                                                                                776398DB 5 Bytes  JMP 00160A08 
.text           C:\Windows\System32\igfxpers.exe[2252] USER32.dll!SetWinEventHook                                                                                    77639F3A 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\igfxpers.exe[2252] USER32.dll!UnhookWinEvent                                                                                     7763C06F 5 Bytes  JMP 001603FC 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!CreateServiceW                                                                                   76419EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!DeleteService                                                                                    7641A07E 5 Bytes  JMP 00170600 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!SetServiceObjectSecurity                                                                         76456CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!ChangeServiceConfigA                                                                             76456DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!ChangeServiceConfigW                                                                             76456F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!ChangeServiceConfig2A                                                                            76457099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!ChangeServiceConfig2W                                                                            764571E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\System32\igfxpers.exe[2252] ADVAPI32.dll!CreateServiceA                                                                                   764572A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ntdll.dll!LdrLoadDll                                                                                          77D59378 5 Bytes  JMP 000901F8 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ntdll.dll!LdrUnloadDll                                                                                        77D6B680 5 Bytes  JMP 000903FC 
.text           C:\Windows\system32\agrsmsvc.exe[2276] KERNEL32.dll!GetBinaryTypeW + 70                                                                              774F2247 1 Byte  [62]
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!CreateServiceW                                                                                   76419EB4 5 Bytes  JMP 000A03FC 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!DeleteService                                                                                    7641A07E 5 Bytes  JMP 000A0600 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!SetServiceObjectSecurity                                                                         76456CD9 5 Bytes  JMP 000A1014 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!ChangeServiceConfigA                                                                             76456DD9 5 Bytes  JMP 000A0804 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!ChangeServiceConfigW                                                                             76456F81 5 Bytes  JMP 000A0A08 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!ChangeServiceConfig2A                                                                            76457099 5 Bytes  JMP 000A0C0C 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!ChangeServiceConfig2W                                                                            764571E1 5 Bytes  JMP 000A0E10 
.text           C:\Windows\system32\agrsmsvc.exe[2276] ADVAPI32.dll!CreateServiceA                                                                                   764572A1 5 Bytes  JMP 000A01F8 
.text           C:\Windows\system32\agrsmsvc.exe[2276] USER32.dll!SetWindowsHookExA                                                                                  77636322 5 Bytes  JMP 000B0600 
.text           C:\Windows\system32\agrsmsvc.exe[2276] USER32.dll!SetWindowsHookExW                                                                                  776387AD 5 Bytes  JMP 000B0804 
.text           C:\Windows\system32\agrsmsvc.exe[2276] USER32.dll!UnhookWindowsHookEx                                                                                776398DB 5 Bytes  JMP 000B0A08 
.text           C:\Windows\system32\agrsmsvc.exe[2276] USER32.dll!SetWinEventHook                                                                                    77639F3A 5 Bytes  JMP 000B01F8 
.text           C:\Windows\system32\agrsmsvc.exe[2276] USER32.dll!UnhookWinEvent                                                                                     7763C06F 5 Bytes  JMP 000B03FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ntdll.dll!LdrLoadDll                                                                            77D59378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ntdll.dll!LdrUnloadDll                                                                          77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] KERNEL32.dll!GetBinaryTypeW + 70                                                                774F2247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] USER32.dll!SetWindowsHookExA                                                                    77636322 5 Bytes  JMP 00170600 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] USER32.dll!SetWindowsHookExW                                                                    776387AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] USER32.dll!UnhookWindowsHookEx                                                                  776398DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] USER32.dll!SetWinEventHook                                                                      77639F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] USER32.dll!UnhookWinEvent                                                                       7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!CreateServiceW                                                                     76419EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!DeleteService                                                                      7641A07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!SetServiceObjectSecurity                                                           76456CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!ChangeServiceConfigA                                                               76456DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!ChangeServiceConfigW                                                               76456F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!ChangeServiceConfig2A                                                              76457099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!ChangeServiceConfig2W                                                              764571E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2296] ADVAPI32.dll!CreateServiceA                                                                     764572A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Winamp\winampa.exe[2480] ntdll.dll!LdrLoadDll                                                                                       77D59378 5 Bytes  JMP 000A01F8 
.text           C:\Program Files\Winamp\winampa.exe[2480] ntdll.dll!LdrUnloadDll                                                                                     77D6B680 5 Bytes  JMP 000A03FC 
.text           C:\Program Files\Winamp\winampa.exe[2480] KERNEL32.dll!GetBinaryTypeW + 70                                                                           774F2247 1 Byte  [62]
.text           C:\Program Files\Winamp\winampa.exe[2480] USER32.dll!SetWindowsHookExA                                                                               77636322 5 Bytes  JMP 000B0600 
.text           C:\Program Files\Winamp\winampa.exe[2480] USER32.dll!SetWindowsHookExW                                                                               776387AD 5 Bytes  JMP 000B0804 
.text           C:\Program Files\Winamp\winampa.exe[2480] USER32.dll!UnhookWindowsHookEx                                                                             776398DB 5 Bytes  JMP 000B0A08 
.text           C:\Program Files\Winamp\winampa.exe[2480] USER32.dll!SetWinEventHook                                                                                 77639F3A 5 Bytes  JMP 000B01F8 
.text           C:\Program Files\Winamp\winampa.exe[2480] USER32.dll!UnhookWinEvent                                                                                  7763C06F 5 Bytes  JMP 000B03FC 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!CreateServiceW                                                                                76419EB4 5 Bytes  JMP 000C03FC 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!DeleteService                                                                                 7641A07E 5 Bytes  JMP 000C0600 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!SetServiceObjectSecurity                                                                      76456CD9 5 Bytes  JMP 000C1014 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!ChangeServiceConfigA                                                                          76456DD9 5 Bytes  JMP 000C0804 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!ChangeServiceConfigW                                                                          76456F81 5 Bytes  JMP 000C0A08 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!ChangeServiceConfig2A                                                                         76457099 5 Bytes  JMP 000C0C0C 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!ChangeServiceConfig2W                                                                         764571E1 5 Bytes  JMP 000C0E10 
.text           C:\Program Files\Winamp\winampa.exe[2480] ADVAPI32.dll!CreateServiceA                                                                                764572A1 5 Bytes  JMP 000C01F8 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ntdll.dll!LdrLoadDll                                                  77D59378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ntdll.dll!LdrUnloadDll                                                77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] KERNEL32.dll!GetBinaryTypeW + 70                                      774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] USER32.dll!SetWindowsHookExA                                          77636322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] USER32.dll!SetWindowsHookExW                                          776387AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] USER32.dll!UnhookWindowsHookEx                                        776398DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] USER32.dll!SetWinEventHook                                            77639F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] USER32.dll!UnhookWinEvent                                             7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!CreateServiceW                                           76419EB4 5 Bytes  JMP 001903FC 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!DeleteService                                            7641A07E 5 Bytes  JMP 00190600 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!SetServiceObjectSecurity                                 76456CD9 5 Bytes  JMP 00191014 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!ChangeServiceConfigA                                     76456DD9 5 Bytes  JMP 00190804 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!ChangeServiceConfigW                                     76456F81 5 Bytes  JMP 00190A08 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!ChangeServiceConfig2A                                    76457099 5 Bytes  JMP 00190C0C 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!ChangeServiceConfig2W                                    764571E1 5 Bytes  JMP 00190E10 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] ADVAPI32.dll!CreateServiceA                                           764572A1 5 Bytes  JMP 001901F8 
.text           C:\Windows\system32\svchost.exe[2528] ntdll.dll!LdrLoadDll                                                                                           77D59378 5 Bytes  JMP 001601F8 
.text           C:\Windows\system32\svchost.exe[2528] ntdll.dll!LdrUnloadDll                                                                                         77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Windows\system32\svchost.exe[2528] KERNEL32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!CreateServiceW                                                                                    76419EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!DeleteService                                                                                     7641A07E 5 Bytes  JMP 00170600 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!SetServiceObjectSecurity                                                                          76456CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!ChangeServiceConfigA                                                                              76456DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!ChangeServiceConfigW                                                                              76456F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!ChangeServiceConfig2A                                                                             76457099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!ChangeServiceConfig2W                                                                             764571E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\system32\svchost.exe[2528] ADVAPI32.dll!CreateServiceA                                                                                    764572A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\system32\svchost.exe[2528] USER32.dll!SetWindowsHookExA                                                                                   77636322 5 Bytes  JMP 00210600 
.text           C:\Windows\system32\svchost.exe[2528] USER32.dll!SetWindowsHookExW                                                                                   776387AD 5 Bytes  JMP 00210804 
.text           C:\Windows\system32\svchost.exe[2528] USER32.dll!UnhookWindowsHookEx                                                                                 776398DB 5 Bytes  JMP 00210A08 
.text           C:\Windows\system32\svchost.exe[2528] USER32.dll!SetWinEventHook                                                                                     77639F3A 5 Bytes  JMP 002101F8 
.text           C:\Windows\system32\svchost.exe[2528] USER32.dll!UnhookWinEvent                                                                                      7763C06F 5 Bytes  JMP 002103FC 
.text           C:\Windows\system32\svchost.exe[2588] ntdll.dll!LdrLoadDll                                                                                           77D59378 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\svchost.exe[2588] ntdll.dll!LdrUnloadDll                                                                                         77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\svchost.exe[2588] KERNEL32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!CreateServiceW                                                                                    76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!DeleteService                                                                                     7641A07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!SetServiceObjectSecurity                                                                          76456CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!ChangeServiceConfigA                                                                              76456DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!ChangeServiceConfigW                                                                              76456F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!ChangeServiceConfig2A                                                                             76457099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!ChangeServiceConfig2W                                                                             764571E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[2588] ADVAPI32.dll!CreateServiceA                                                                                    764572A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWindowsHookExA                                                                                   77636322 5 Bytes  JMP 000D0600 
.text           C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWindowsHookExW                                                                                   776387AD 5 Bytes  JMP 000D0804 
.text           C:\Windows\system32\svchost.exe[2588] USER32.dll!UnhookWindowsHookEx                                                                                 776398DB 5 Bytes  JMP 000D0A08 
.text           C:\Windows\system32\svchost.exe[2588] USER32.dll!SetWinEventHook                                                                                     77639F3A 5 Bytes  JMP 000D01F8 
.text           C:\Windows\system32\svchost.exe[2588] USER32.dll!UnhookWinEvent                                                                                      7763C06F 5 Bytes  JMP 000D03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ntdll.dll!LdrLoadDll                                                             77D59378 5 Bytes  JMP 001601F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ntdll.dll!LdrUnloadDll                                                           77D6B680 5 Bytes  JMP 001603FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] KERNEL32.dll!GetBinaryTypeW + 70                                                 774F2247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] USER32.dll!SetWindowsHookExA                                                     77636322 5 Bytes  JMP 00170600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] USER32.dll!SetWindowsHookExW                                                     776387AD 5 Bytes  JMP 00170804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] USER32.dll!UnhookWindowsHookEx                                                   776398DB 5 Bytes  JMP 00170A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] USER32.dll!SetWinEventHook                                                       77639F3A 5 Bytes  JMP 001701F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] USER32.dll!UnhookWinEvent                                                        7763C06F 5 Bytes  JMP 001703FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!CreateServiceW                                                      76419EB4 5 Bytes  JMP 001803FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!DeleteService                                                       7641A07E 5 Bytes  JMP 00180600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!SetServiceObjectSecurity                                            76456CD9 5 Bytes  JMP 00181014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!ChangeServiceConfigA                                                76456DD9 5 Bytes  JMP 00180804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!ChangeServiceConfigW                                                76456F81 5 Bytes  JMP 00180A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!ChangeServiceConfig2A                                               76457099 5 Bytes  JMP 00180C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!ChangeServiceConfig2W                                               764571E1 5 Bytes  JMP 00180E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] ADVAPI32.dll!CreateServiceA                                                      764572A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\system32\TODDSrv.exe[2660] ntdll.dll!LdrLoadDll                                                                                           77D59378 5 Bytes  JMP 001501F8 
.text           C:\Windows\system32\TODDSrv.exe[2660] ntdll.dll!LdrUnloadDll                                                                                         77D6B680 5 Bytes  JMP 001503FC 
.text           C:\Windows\system32\TODDSrv.exe[2660] KERNEL32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\TODDSrv.exe[2660] USER32.dll!SetWindowsHookExA                                                                                   77636322 5 Bytes  JMP 00160600 
.text           C:\Windows\system32\TODDSrv.exe[2660] USER32.dll!SetWindowsHookExW                                                                                   776387AD 5 Bytes  JMP 00160804 
.text           C:\Windows\system32\TODDSrv.exe[2660] USER32.dll!UnhookWindowsHookEx                                                                                 776398DB 5 Bytes  JMP 00160A08 
.text           C:\Windows\system32\TODDSrv.exe[2660] USER32.dll!SetWinEventHook                                                                                     77639F3A 5 Bytes  JMP 001601F8 
.text           C:\Windows\system32\TODDSrv.exe[2660] USER32.dll!UnhookWinEvent                                                                                      7763C06F 5 Bytes  JMP 001603FC 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!CreateServiceW                                                                                    76419EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!DeleteService                                                                                     7641A07E 5 Bytes  JMP 00170600 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!SetServiceObjectSecurity                                                                          76456CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!ChangeServiceConfigA                                                                              76456DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!ChangeServiceConfigW                                                                              76456F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!ChangeServiceConfig2A                                                                             76457099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!ChangeServiceConfig2W                                                                             764571E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\system32\TODDSrv.exe[2660] ADVAPI32.dll!CreateServiceA                                                                                    764572A1 5 Bytes  JMP 001701F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ntdll.dll!LdrLoadDll                                                                         77D59378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ntdll.dll!LdrUnloadDll                                                                       77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] KERNEL32.dll!GetBinaryTypeW + 70                                                             774F2247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!CreateServiceW                                                                  76419EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!DeleteService                                                                   7641A07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!SetServiceObjectSecurity                                                        76456CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!ChangeServiceConfigA                                                            76456DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!ChangeServiceConfigW                                                            76456F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!ChangeServiceConfig2A                                                           76457099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!ChangeServiceConfig2W                                                           764571E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] ADVAPI32.dll!CreateServiceA                                                                  764572A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] USER32.dll!SetWindowsHookExA                                                                 77636322 5 Bytes  JMP 00190600 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] USER32.dll!SetWindowsHookExW                                                                 776387AD 5 Bytes  JMP 00190804 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] USER32.dll!UnhookWindowsHookEx                                                               776398DB 5 Bytes  JMP 00190A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] USER32.dll!SetWinEventHook                                                                   77639F3A 5 Bytes  JMP 001901F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[2720] USER32.dll!UnhookWinEvent                                                                    7763C06F 5 Bytes  JMP 001903FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ntdll.dll!LdrLoadDll                                                             77D59378 5 Bytes  JMP 001501F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ntdll.dll!LdrUnloadDll                                                           77D6B680 5 Bytes  JMP 001503FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] KERNEL32.dll!GetBinaryTypeW + 70                                                 774F2247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!CreateServiceW                                                      76419EB4 5 Bytes  JMP 001603FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!DeleteService                                                       7641A07E 5 Bytes  JMP 00160600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!SetServiceObjectSecurity                                            76456CD9 5 Bytes  JMP 00161014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!ChangeServiceConfigA                                                76456DD9 5 Bytes  JMP 00160804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!ChangeServiceConfigW                                                76456F81 5 Bytes  JMP 00160A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!ChangeServiceConfig2A                                               76457099 5 Bytes  JMP 00160C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!ChangeServiceConfig2W                                               764571E1 5 Bytes  JMP 00160E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] ADVAPI32.dll!CreateServiceA                                                      764572A1 5 Bytes  JMP 001601F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] USER32.dll!SetWindowsHookExA                                                     77636322 5 Bytes  JMP 00170600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] USER32.dll!SetWindowsHookExW                                                     776387AD 5 Bytes  JMP 00170804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] USER32.dll!UnhookWindowsHookEx                                                   776398DB 5 Bytes  JMP 00170A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] USER32.dll!SetWinEventHook                                                       77639F3A 5 Bytes  JMP 001701F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[2772] USER32.dll!UnhookWinEvent                                                        7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ntdll.dll!LdrLoadDll                                                                       77D59378 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ntdll.dll!LdrUnloadDll                                                                     77D6B680 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] KERNEL32.dll!GetBinaryTypeW + 70                                                           774F2247 1 Byte  [62]
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] USER32.dll!SetWindowsHookExA                                                               77636322 5 Bytes  JMP 00180600 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] USER32.dll!SetWindowsHookExW                                                               776387AD 5 Bytes  JMP 00180804 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] USER32.dll!UnhookWindowsHookEx                                                             776398DB 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] USER32.dll!SetWinEventHook                                                                 77639F3A 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] USER32.dll!UnhookWinEvent                                                                  7763C06F 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!CreateServiceW                                                                76419EB4 5 Bytes  JMP 001903FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!DeleteService                                                                 7641A07E 5 Bytes  JMP 00190600 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!SetServiceObjectSecurity                                                      76456CD9 5 Bytes  JMP 00191014 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!ChangeServiceConfigA                                                          76456DD9 5 Bytes  JMP 00190804 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!ChangeServiceConfigW                                                          76456F81 5 Bytes  JMP 00190A08 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!ChangeServiceConfig2A                                                         76457099 5 Bytes  JMP 00190C0C 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!ChangeServiceConfig2W                                                         764571E1 5 Bytes  JMP 00190E10 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] ADVAPI32.dll!CreateServiceA                                                                764572A1 5 Bytes  JMP 001901F8 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ntdll.dll!LdrLoadDll                                                              77D59378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ntdll.dll!LdrUnloadDll                                                            77D6B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] KERNEL32.dll!GetBinaryTypeW + 70                                                  774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!CreateServiceW                                                       76419EB4 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!DeleteService                                                        7641A07E 5 Bytes  JMP 00160600 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!SetServiceObjectSecurity                                             76456CD9 5 Bytes  JMP 00161014 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!ChangeServiceConfigA                                                 76456DD9 5 Bytes  JMP 00160804 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!ChangeServiceConfigW                                                 76456F81 5 Bytes  JMP 00160A08 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!ChangeServiceConfig2A                                                76457099 5 Bytes  JMP 00160C0C 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!ChangeServiceConfig2W                                                764571E1 5 Bytes  JMP 00160E10 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2800] ADVAPI32.dll!CreateServiceA                                                       764572A1 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\svchost.exe[2820] ntdll.dll!LdrLoadDll                                                                                           77D59378 5 Bytes  JMP 000601F8 
.text           C:\Windows\System32\svchost.exe[2820] ntdll.dll!LdrUnloadDll                                                                                         77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Windows\System32\svchost.exe[2820] KERNEL32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!CreateServiceW                                                                                    76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!DeleteService                                                                                     7641A07E 5 Bytes  JMP 00070600 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!SetServiceObjectSecurity                                                                          76456CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!ChangeServiceConfigA                                                                              76456DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!ChangeServiceConfigW                                                                              76456F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!ChangeServiceConfig2A                                                                             76457099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!ChangeServiceConfig2W                                                                             764571E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\System32\svchost.exe[2820] ADVAPI32.dll!CreateServiceA                                                                                    764572A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ntdll.dll!LdrLoadDll                                                                                     77D59378 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ntdll.dll!LdrUnloadDll                                                                                   77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\SearchIndexer.exe[2872] KERNEL32.dll!GetBinaryTypeW + 70                                                                         774F2247 1 Byte  [62]
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!CreateServiceW                                                                              76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!DeleteService                                                                               7641A07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!SetServiceObjectSecurity                                                                    76456CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!ChangeServiceConfigA                                                                        76456DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!ChangeServiceConfigW                                                                        76456F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!ChangeServiceConfig2A                                                                       76457099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!ChangeServiceConfig2W                                                                       764571E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\SearchIndexer.exe[2872] ADVAPI32.dll!CreateServiceA                                                                              764572A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\SearchIndexer.exe[2872] USER32.dll!SetWindowsHookExA                                                                             77636322 5 Bytes  JMP 00080600 
.text           C:\Windows\system32\SearchIndexer.exe[2872] USER32.dll!SetWindowsHookExW                                                                             776387AD 5 Bytes  JMP 00080804 
.text           C:\Windows\system32\SearchIndexer.exe[2872] USER32.dll!UnhookWindowsHookEx                                                                           776398DB 5 Bytes  JMP 00080A08 
.text           C:\Windows\system32\SearchIndexer.exe[2872] USER32.dll!SetWinEventHook                                                                               77639F3A 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\SearchIndexer.exe[2872] USER32.dll!UnhookWinEvent                                                                                7763C06F 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ntdll.dll!LdrLoadDll                                                                              77D59378 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ntdll.dll!LdrUnloadDll                                                                            77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] KERNEL32.dll!GetBinaryTypeW + 70                                                                  774F2247 1 Byte  [62]
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!CreateServiceW                                                                       76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!DeleteService                                                                        7641A07E 5 Bytes  JMP 00070600 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!SetServiceObjectSecurity                                                             76456CD9 5 Bytes  JMP 00071014 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!ChangeServiceConfigA                                                                 76456DD9 5 Bytes  JMP 00070804 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!ChangeServiceConfigW                                                                 76456F81 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!ChangeServiceConfig2A                                                                76457099 5 Bytes  JMP 00070C0C 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!ChangeServiceConfig2W                                                                764571E1 5 Bytes  JMP 00070E10 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] ADVAPI32.dll!CreateServiceA                                                                       764572A1 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] USER32.dll!SetWindowsHookExA                                                                      77636322 5 Bytes  JMP 00080600 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] USER32.dll!SetWindowsHookExW                                                                      776387AD 5 Bytes  JMP 00080804 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] USER32.dll!UnhookWindowsHookEx                                                                    776398DB 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] USER32.dll!SetWinEventHook                                                                        77639F3A 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3108] USER32.dll!UnhookWinEvent                                                                         7763C06F 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ntdll.dll!LdrLoadDll                                                                     77D59378 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ntdll.dll!LdrUnloadDll                                                                   77D6B680 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] KERNEL32.dll!SetUnhandledExceptionFilter                                                 774CA84F 5 Bytes  [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] KERNEL32.dll!GetBinaryTypeW + 70                                                         774F2247 1 Byte  [62]
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] USER32.dll!SetWindowsHookExA                                                             77636322 5 Bytes  JMP 00060600 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] USER32.dll!SetWindowsHookExW                                                             776387AD 5 Bytes  JMP 00060804 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] USER32.dll!UnhookWindowsHookEx                                                           776398DB 5 Bytes  JMP 00060A08 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] USER32.dll!SetWinEventHook                                                               77639F3A 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] USER32.dll!UnhookWinEvent                                                                7763C06F 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!CreateServiceW                                                              76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!DeleteService                                                               7641A07E 5 Bytes  JMP 00070600 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!SetServiceObjectSecurity                                                    76456CD9 5 Bytes  JMP 00071014 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!ChangeServiceConfigA                                                        76456DD9 5 Bytes  JMP 00070804 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!ChangeServiceConfigW                                                        76456F81 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!ChangeServiceConfig2A                                                       76457099 5 Bytes  JMP 00070C0C 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!ChangeServiceConfig2W                                                       764571E1 5 Bytes  JMP 00070E10 
.text           C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] ADVAPI32.dll!CreateServiceA                                                              764572A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ntdll.dll!LdrLoadDll                                                                                    77D59378 5 Bytes  JMP 001601F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ntdll.dll!LdrUnloadDll                                                                                  77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] KERNEL32.dll!GetBinaryTypeW + 70                                                                        774F2247 1 Byte  [62]
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!CreateServiceW                                                                             76419EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!DeleteService                                                                              7641A07E 5 Bytes  JMP 00170600 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!SetServiceObjectSecurity                                                                   76456CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!ChangeServiceConfigA                                                                       76456DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!ChangeServiceConfigW                                                                       76456F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!ChangeServiceConfig2A                                                                      76457099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!ChangeServiceConfig2W                                                                      764571E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] ADVAPI32.dll!CreateServiceA                                                                             764572A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] USER32.dll!SetWindowsHookExA                                                                            77636322 5 Bytes  JMP 00280600 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] USER32.dll!SetWindowsHookExW                                                                            776387AD 5 Bytes  JMP 00280804 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] USER32.dll!UnhookWindowsHookEx                                                                          776398DB 5 Bytes  JMP 00280A08 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] USER32.dll!SetWinEventHook                                                                              77639F3A 5 Bytes  JMP 002801F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] USER32.dll!UnhookWinEvent                                                                               7763C06F 5 Bytes  JMP 002803FC 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ntdll.dll!LdrLoadDll                                                                             77D59378 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ntdll.dll!LdrUnloadDll                                                                           77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] KERNEL32.dll!GetBinaryTypeW + 70                                                                 774F2247 1 Byte  [62]
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!CreateServiceW                                                                      76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!DeleteService                                                                       7641A07E 5 Bytes  JMP 00070600 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!SetServiceObjectSecurity                                                            76456CD9 5 Bytes  JMP 00071014 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!ChangeServiceConfigA                                                                76456DD9 5 Bytes  JMP 00070804 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!ChangeServiceConfigW                                                                76456F81 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!ChangeServiceConfig2A                                                               76457099 5 Bytes  JMP 00070C0C 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!ChangeServiceConfig2W                                                               764571E1 5 Bytes  JMP 00070E10 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] ADVAPI32.dll!CreateServiceA                                                                      764572A1 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] USER32.dll!SetWindowsHookExA                                                                     77636322 5 Bytes  JMP 00090600 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] USER32.dll!SetWindowsHookExW                                                                     776387AD 5 Bytes  JMP 00090804 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] USER32.dll!UnhookWindowsHookEx                                                                   776398DB 5 Bytes  JMP 00090A08 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] USER32.dll!SetWinEventHook                                                                       77639F3A 5 Bytes  JMP 000901F8 
.text           C:\Program Files\Windows Defender\MSASCui.exe[3324] USER32.dll!UnhookWinEvent                                                                        7763C06F 5 Bytes  JMP 000903FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ntdll.dll!LdrLoadDll                                                                         77D59378 5 Bytes  JMP 002701F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ntdll.dll!LdrUnloadDll                                                                       77D6B680 5 Bytes  JMP 002703FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] KERNEL32.dll!GetBinaryTypeW + 70                                                             774F2247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!CreateServiceW                                                                  76419EB4 5 Bytes  JMP 002903FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!DeleteService                                                                   7641A07E 5 Bytes  JMP 00290600 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!SetServiceObjectSecurity                                                        76456CD9 5 Bytes  JMP 00291014 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!ChangeServiceConfigA                                                            76456DD9 5 Bytes  JMP 00290804 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!ChangeServiceConfigW                                                            76456F81 5 Bytes  JMP 00290A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!ChangeServiceConfig2A                                                           76457099 5 Bytes  JMP 00290C0C 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!ChangeServiceConfig2W                                                           764571E1 5 Bytes  JMP 00290E10 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] ADVAPI32.dll!CreateServiceA                                                                  764572A1 5 Bytes  JMP 002901F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] USER32.dll!SetWindowsHookExA                                                                 77636322 5 Bytes  JMP 002A0600 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] USER32.dll!SetWindowsHookExW                                                                 776387AD 5 Bytes  JMP 002A0804 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] USER32.dll!UnhookWindowsHookEx                                                               776398DB 5 Bytes  JMP 002A0A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] USER32.dll!SetWinEventHook                                                                   77639F3A 5 Bytes  JMP 002A01F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] USER32.dll!UnhookWinEvent                                                                    7763C06F 5 Bytes  JMP 002A03FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ntdll.dll!LdrLoadDll                                                                        77D59378 5 Bytes  JMP 001701F8 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ntdll.dll!LdrUnloadDll                                                                      77D6B680 5 Bytes  JMP 001703FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] KERNEL32.dll!GetBinaryTypeW + 70                                                            774F2247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] USER32.dll!SetWindowsHookExA                                                                77636322 5 Bytes  JMP 00180600 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] USER32.dll!SetWindowsHookExW                                                                776387AD 5 Bytes  JMP 00180804 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] USER32.dll!UnhookWindowsHookEx                                                              776398DB 5 Bytes  JMP 00180A08 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] USER32.dll!SetWinEventHook                                                                  77639F3A 5 Bytes  JMP 001801F8 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] USER32.dll!UnhookWinEvent                                                                   7763C06F 5 Bytes  JMP 001803FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!CreateServiceW                                                                 76419EB4 5 Bytes  JMP 001903FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!DeleteService                                                                  7641A07E 5 Bytes  JMP 00190600 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!SetServiceObjectSecurity                                                       76456CD9 5 Bytes  JMP 00191014 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!ChangeServiceConfigA                                                           76456DD9 5 Bytes  JMP 00190804 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!ChangeServiceConfigW                                                           76456F81 5 Bytes  JMP 00190A08 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!ChangeServiceConfig2A                                                          76457099 5 Bytes  JMP 00190C0C 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!ChangeServiceConfig2W                                                          764571E1 5 Bytes  JMP 00190E10 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] ADVAPI32.dll!CreateServiceA                                                                 764572A1 5 Bytes  JMP 001901F8 
.text           C:\Program Files\Alwil Software\Avast5\AvastUI.exe[3600] kernel32.dll!GetBinaryTypeW + 70                                                            774F2247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ntdll.dll!LdrLoadDll                                                                          77D59378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ntdll.dll!LdrUnloadDll                                                                        77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] KERNEL32.dll!GetBinaryTypeW + 70                                                              774F2247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!CreateServiceW                                                                   76419EB4 5 Bytes  JMP 001703FC 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!DeleteService                                                                    7641A07E 5 Bytes  JMP 00170600 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!SetServiceObjectSecurity                                                         76456CD9 5 Bytes  JMP 00171014 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!ChangeServiceConfigA                                                             76456DD9 5 Bytes  JMP 00170804 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!ChangeServiceConfigW                                                             76456F81 5 Bytes  JMP 00170A08 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!ChangeServiceConfig2A                                                            76457099 5 Bytes  JMP 00170C0C 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!ChangeServiceConfig2W                                                            764571E1 5 Bytes  JMP 00170E10 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] ADVAPI32.dll!CreateServiceA                                                                   764572A1 5 Bytes  JMP 001701F8 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] USER32.dll!SetWindowsHookExA                                                                  77636322 5 Bytes  JMP 001A0600 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] USER32.dll!SetWindowsHookExW                                                                  776387AD 5 Bytes  JMP 001A0804 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] USER32.dll!UnhookWindowsHookEx                                                                776398DB 5 Bytes  JMP 001A0A08 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] USER32.dll!SetWinEventHook                                                                    77639F3A 5 Bytes  JMP 001A01F8 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] USER32.dll!UnhookWinEvent                                                                     7763C06F 5 Bytes  JMP 001A03FC 
.text           C:\Windows\System32\rundll32.exe[3724] ntdll.dll!LdrLoadDll                                                                                          77D59378 5 Bytes  JMP 000701F8 
.text           C:\Windows\System32\rundll32.exe[3724] ntdll.dll!LdrUnloadDll                                                                                        77D6B680 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\rundll32.exe[3724] KERNEL32.dll!GetBinaryTypeW + 70                                                                              774F2247 1 Byte  [62]
.text           C:\Windows\System32\rundll32.exe[3724] USER32.dll!SetWindowsHookExA                                                                                  77636322 5 Bytes  JMP 00080600 
.text           C:\Windows\System32\rundll32.exe[3724] USER32.dll!SetWindowsHookExW                                                                                  776387AD 5 Bytes  JMP 00080804 
.text           C:\Windows\System32\rundll32.exe[3724] USER32.dll!UnhookWindowsHookEx                                                                                776398DB 5 Bytes  JMP 00080A08 
.text           C:\Windows\System32\rundll32.exe[3724] USER32.dll!SetWinEventHook                                                                                    77639F3A 5 Bytes  JMP 000801F8 
.text           C:\Windows\System32\rundll32.exe[3724] USER32.dll!UnhookWinEvent                                                                                     7763C06F 5 Bytes  JMP 000803FC 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!CreateServiceW                                                                                   76419EB4 5 Bytes  JMP 000903FC 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!DeleteService                                                                                    7641A07E 5 Bytes  JMP 00090600 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!SetServiceObjectSecurity                                                                         76456CD9 5 Bytes  JMP 00091014 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!ChangeServiceConfigA                                                                             76456DD9 5 Bytes  JMP 00090804 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!ChangeServiceConfigW                                                                             76456F81 5 Bytes  JMP 00090A08 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!ChangeServiceConfig2A                                                                            76457099 5 Bytes  JMP 00090C0C 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!ChangeServiceConfig2W                                                                            764571E1 5 Bytes  JMP 00090E10 
.text           C:\Windows\System32\rundll32.exe[3724] ADVAPI32.dll!CreateServiceA                                                                                   764572A1 5 Bytes  JMP 000901F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ntdll.dll!LdrLoadDll                                                                             77D59378 5 Bytes  JMP 002701F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ntdll.dll!LdrUnloadDll                                                                           77D6B680 5 Bytes  JMP 002703FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] KERNEL32.dll!GetBinaryTypeW + 70                                                                 774F2247 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] USER32.dll!SetWindowsHookExA                                                                     77636322 5 Bytes  JMP 00280600 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] USER32.dll!SetWindowsHookExW                                                                     776387AD 5 Bytes  JMP 00280804 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] USER32.dll!UnhookWindowsHookEx                                                                   776398DB 5 Bytes  JMP 00280A08 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] USER32.dll!SetWinEventHook                                                                       77639F3A 5 Bytes  JMP 002801F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] USER32.dll!UnhookWinEvent                                                                        7763C06F 5 Bytes  JMP 002803FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!CreateServiceW                                                                      76419EB4 5 Bytes  JMP 002903FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!DeleteService                                                                       7641A07E 5 Bytes  JMP 00290600 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!SetServiceObjectSecurity                                                            76456CD9 5 Bytes  JMP 00291014 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!ChangeServiceConfigA                                                                76456DD9 5 Bytes  JMP 00290804 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!ChangeServiceConfigW                                                                76456F81 5 Bytes  JMP 00290A08 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!ChangeServiceConfig2A                                                               76457099 5 Bytes  JMP 00290C0C 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!ChangeServiceConfig2W                                                               764571E1 5 Bytes  JMP 00290E10 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] ADVAPI32.dll!CreateServiceA                                                                      764572A1 5 Bytes  JMP 002901F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ntdll.dll!LdrLoadDll                                                                77D59378 5 Bytes  JMP 002801F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ntdll.dll!LdrUnloadDll                                                              77D6B680 5 Bytes  JMP 002803FC 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] KERNEL32.dll!GetBinaryTypeW + 70                                                    774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!CreateServiceW                                                         76419EB4 5 Bytes  JMP 002903FC 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!DeleteService                                                          7641A07E 5 Bytes  JMP 00290600 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!SetServiceObjectSecurity                                               76456CD9 5 Bytes  JMP 00291014 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!ChangeServiceConfigA                                                   76456DD9 5 Bytes  JMP 00290804 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!ChangeServiceConfigW                                                   76456F81 5 Bytes  JMP 00290A08 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!ChangeServiceConfig2A                                                  76457099 5 Bytes  JMP 00290C0C 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!ChangeServiceConfig2W                                                  764571E1 5 Bytes  JMP 00290E10 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] ADVAPI32.dll!CreateServiceA                                                         764572A1 5 Bytes  JMP 002901F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] USER32.dll!SetWindowsHookExA                                                        77636322 5 Bytes  JMP 002A0600 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] USER32.dll!SetWindowsHookExW                                                        776387AD 5 Bytes  JMP 002A0804 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] USER32.dll!UnhookWindowsHookEx                                                      776398DB 5 Bytes  JMP 002A0A08 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] USER32.dll!SetWinEventHook                                                          77639F3A 5 Bytes  JMP 002A01F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] USER32.dll!UnhookWinEvent                                                           7763C06F 5 Bytes  JMP 002A03FC 
.text           C:\Windows\RtHDVCpl.exe[3860] ntdll.dll!LdrLoadDll                                                                                                   77D59378 5 Bytes  JMP 001701F8 
.text           C:\Windows\RtHDVCpl.exe[3860] ntdll.dll!LdrUnloadDll                                                                                                 77D6B680 5 Bytes  JMP 001703FC 
.text           C:\Windows\RtHDVCpl.exe[3860] KERNEL32.dll!GetBinaryTypeW + 70                                                                                       774F2247 1 Byte  [62]
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!CreateServiceW                                                                                            76419EB4 5 Bytes  JMP 001803FC 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!DeleteService                                                                                             7641A07E 5 Bytes  JMP 00180600 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!SetServiceObjectSecurity                                                                                  76456CD9 5 Bytes  JMP 00181014 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!ChangeServiceConfigA                                                                                      76456DD9 5 Bytes  JMP 00180804 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!ChangeServiceConfigW                                                                                      76456F81 5 Bytes  JMP 00180A08 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!ChangeServiceConfig2A                                                                                     76457099 5 Bytes  JMP 00180C0C 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!ChangeServiceConfig2W                                                                                     764571E1 5 Bytes  JMP 00180E10 
.text           C:\Windows\RtHDVCpl.exe[3860] ADVAPI32.dll!CreateServiceA                                                                                            764572A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\RtHDVCpl.exe[3860] USER32.dll!SetWindowsHookExA                                                                                           77636322 5 Bytes  JMP 00190600 
.text           C:\Windows\RtHDVCpl.exe[3860] USER32.dll!SetWindowsHookExW                                                                                           776387AD 5 Bytes  JMP 00190804 
.text           C:\Windows\RtHDVCpl.exe[3860] USER32.dll!UnhookWindowsHookEx                                                                                         776398DB 5 Bytes  JMP 00190A08 
.text           C:\Windows\RtHDVCpl.exe[3860] USER32.dll!SetWinEventHook                                                                                             77639F3A 5 Bytes  JMP 001901F8 
.text           C:\Windows\RtHDVCpl.exe[3860] USER32.dll!UnhookWinEvent                                                                                              7763C06F 5 Bytes  JMP 001903FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ntdll.dll!LdrLoadDll                                                             77D59378 5 Bytes  JMP 002701F8 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ntdll.dll!LdrUnloadDll                                                           77D6B680 5 Bytes  JMP 002703FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] KERNEL32.dll!GetBinaryTypeW + 70                                                 774F2247 1 Byte  [62]
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] USER32.dll!SetWindowsHookExA                                                     77636322 5 Bytes  JMP 00280600 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] USER32.dll!SetWindowsHookExW                                                     776387AD 5 Bytes  JMP 00280804 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] USER32.dll!UnhookWindowsHookEx                                                   776398DB 5 Bytes  JMP 00280A08 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] USER32.dll!SetWinEventHook                                                       77639F3A 5 Bytes  JMP 002801F8 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] USER32.dll!UnhookWinEvent                                                        7763C06F 5 Bytes  JMP 002803FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!CreateServiceW                                                      76419EB4 5 Bytes  JMP 002903FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!DeleteService                                                       7641A07E 5 Bytes  JMP 00290600 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!SetServiceObjectSecurity                                            76456CD9 5 Bytes  JMP 00291014 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!ChangeServiceConfigA                                                76456DD9 5 Bytes  JMP 00290804 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!ChangeServiceConfigW                                                76456F81 5 Bytes  JMP 00290A08 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!ChangeServiceConfig2A                                               76457099 5 Bytes  JMP 00290C0C 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!ChangeServiceConfig2W                                               764571E1 5 Bytes  JMP 00290E10 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] ADVAPI32.dll!CreateServiceA                                                      764572A1 5 Bytes  JMP 002901F8 
.text           C:\Windows\System32\igfxtray.exe[3920] ntdll.dll!LdrLoadDll                                                                                          77D59378 5 Bytes  JMP 001501F8 
.text           C:\Windows\System32\igfxtray.exe[3920] ntdll.dll!LdrUnloadDll                                                                                        77D6B680 5 Bytes  JMP 001503FC 
.text           C:\Windows\System32\igfxtray.exe[3920] KERNEL32.dll!GetBinaryTypeW + 70                                                                              774F2247 1 Byte  [62]
.text           C:\Windows\System32\igfxtray.exe[3920] USER32.dll!SetWindowsHookExA                                                                                  77636322 5 Bytes  JMP 00170600 
.text           C:\Windows\System32\igfxtray.exe[3920] USER32.dll!SetWindowsHookExW                                                                                  776387AD 5 Bytes  JMP 00170804 
.text           C:\Windows\System32\igfxtray.exe[3920] USER32.dll!UnhookWindowsHookEx                                                                                776398DB 5 Bytes  JMP 00170A08 
.text           C:\Windows\System32\igfxtray.exe[3920] USER32.dll!SetWinEventHook                                                                                    77639F3A 5 Bytes  JMP 001701F8 
.text           C:\Windows\System32\igfxtray.exe[3920] USER32.dll!UnhookWinEvent                                                                                     7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!CreateServiceW                                                                                   76419EB4 5 Bytes  JMP 001803FC 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!DeleteService                                                                                    7641A07E 5 Bytes  JMP 00180600 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!SetServiceObjectSecurity                                                                         76456CD9 5 Bytes  JMP 00181014 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!ChangeServiceConfigA                                                                             76456DD9 5 Bytes  JMP 00180804 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!ChangeServiceConfigW                                                                             76456F81 5 Bytes  JMP 00180A08 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!ChangeServiceConfig2A                                                                            76457099 5 Bytes  JMP 00180C0C 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!ChangeServiceConfig2W                                                                            764571E1 5 Bytes  JMP 00180E10 
.text           C:\Windows\System32\igfxtray.exe[3920] ADVAPI32.dll!CreateServiceA                                                                                   764572A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ntdll.dll!LdrLoadDll                                                                           77D59378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ntdll.dll!LdrUnloadDll                                                                         77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] KERNEL32.dll!GetBinaryTypeW + 70                                                               774F2247 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] USER32.dll!SetWindowsHookExA                                                                   77636322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] USER32.dll!SetWindowsHookExW                                                                   776387AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] USER32.dll!UnhookWindowsHookEx                                                                 776398DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] USER32.dll!SetWinEventHook                                                                     77639F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] USER32.dll!UnhookWinEvent                                                                      7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!CreateServiceW                                                                    76419EB4 5 Bytes  JMP 002803FC 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!DeleteService                                                                     7641A07E 5 Bytes  JMP 00280600 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!SetServiceObjectSecurity                                                          76456CD9 5 Bytes  JMP 00281014 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!ChangeServiceConfigA                                                              76456DD9 5 Bytes  JMP 00280804 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!ChangeServiceConfigW                                                              76456F81 5 Bytes  JMP 00280A08 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!ChangeServiceConfig2A                                                             76457099 5 Bytes  JMP 00280C0C 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!ChangeServiceConfig2W                                                             764571E1 5 Bytes  JMP 00280E10 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] ADVAPI32.dll!CreateServiceA                                                                    764572A1 5 Bytes  JMP 002801F8 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ntdll.dll!LdrLoadDll                                                                                77D59378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ntdll.dll!LdrUnloadDll                                                                              77D6B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] KERNEL32.dll!GetBinaryTypeW + 70                                                                    774F2247 1 Byte  [62]
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!CreateServiceW                                                                         76419EB4 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!DeleteService                                                                          7641A07E 5 Bytes  JMP 00060600 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!SetServiceObjectSecurity                                                               76456CD9 5 Bytes  JMP 00061014 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!ChangeServiceConfigA                                                                   76456DD9 5 Bytes  JMP 00060804 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!ChangeServiceConfigW                                                                   76456F81 5 Bytes  JMP 00060A08 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!ChangeServiceConfig2A                                                                  76457099 3 Bytes  JMP 00060C0C 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!ChangeServiceConfig2A + 4                                                              7645709D 1 Byte  [89]
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!ChangeServiceConfig2W                                                                  764571E1 5 Bytes  JMP 00060E10 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] ADVAPI32.dll!CreateServiceA                                                                         764572A1 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] USER32.dll!SetWindowsHookExA                                                                        77636322 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] USER32.dll!SetWindowsHookExW                                                                        776387AD 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] USER32.dll!UnhookWindowsHookEx                                                                      776398DB 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] USER32.dll!SetWinEventHook                                                                          77639F3A 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\SearchProtocolHost.exe[4256] USER32.dll!UnhookWinEvent                                                                           7763C06F 5 Bytes  JMP 000703FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ntdll.dll!LdrLoadDll                                                             77D59378 5 Bytes  JMP 001501F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ntdll.dll!LdrUnloadDll                                                           77D6B680 5 Bytes  JMP 001503FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] KERNEL32.dll!GetBinaryTypeW + 70                                                 774F2247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] USER32.dll!SetWindowsHookExA                                                     77636322 5 Bytes  JMP 00190600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] USER32.dll!SetWindowsHookExW                                                     776387AD 5 Bytes  JMP 00190804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] USER32.dll!UnhookWindowsHookEx                                                   776398DB 5 Bytes  JMP 00190A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] USER32.dll!SetWinEventHook                                                       77639F3A 5 Bytes  JMP 001901F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] USER32.dll!UnhookWinEvent                                                        7763C06F 5 Bytes  JMP 001903FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!CreateServiceW                                                      76419EB4 5 Bytes  JMP 001A03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!DeleteService                                                       7641A07E 5 Bytes  JMP 001A0600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!SetServiceObjectSecurity                                            76456CD9 5 Bytes  JMP 001A1014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!ChangeServiceConfigA                                                76456DD9 5 Bytes  JMP 001A0804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!ChangeServiceConfigW                                                76456F81 5 Bytes  JMP 001A0A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!ChangeServiceConfig2A                                               76457099 5 Bytes  JMP 001A0C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!ChangeServiceConfig2W                                               764571E1 5 Bytes  JMP 001A0E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] ADVAPI32.dll!CreateServiceA                                                      764572A1 5 Bytes  JMP 001A01F8 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ntdll.dll!LdrLoadDll                                                                                   77D59378 5 Bytes  JMP 001601F8 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ntdll.dll!LdrUnloadDll                                                                                 77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] KERNEL32.dll!GetBinaryTypeW + 70                                                                       774F2247 1 Byte  [62]
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!CreateServiceW                                                                            76419EB4 5 Bytes  JMP 001703FC 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!DeleteService                                                                             7641A07E 5 Bytes  JMP 00170600 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!SetServiceObjectSecurity                                                                  76456CD9 5 Bytes  JMP 00171014 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!ChangeServiceConfigA                                                                      76456DD9 5 Bytes  JMP 00170804 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!ChangeServiceConfigW                                                                      76456F81 5 Bytes  JMP 00170A08 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!ChangeServiceConfig2A                                                                     76457099 5 Bytes  JMP 00170C0C 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!ChangeServiceConfig2W                                                                     764571E1 5 Bytes  JMP 00170E10 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] ADVAPI32.dll!CreateServiceA                                                                            764572A1 5 Bytes  JMP 001701F8 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] USER32.dll!SetWindowsHookExA                                                                           77636322 5 Bytes  JMP 00180600 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] USER32.dll!SetWindowsHookExW                                                                           776387AD 5 Bytes  JMP 00180804 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] USER32.dll!UnhookWindowsHookEx                                                                         776398DB 5 Bytes  JMP 00180A08 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] USER32.dll!SetWinEventHook                                                                             77639F3A 5 Bytes  JMP 001801F8 
.text           C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] USER32.dll!UnhookWinEvent                                                                              7763C06F 5 Bytes  JMP 001803FC 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ntdll.dll!LdrLoadDll                                                                                     77D59378 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ntdll.dll!LdrUnloadDll                                                                                   77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] KERNEL32.dll!GetBinaryTypeW + 70                                                                         774F2247 1 Byte  [62]
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!CreateServiceW                                                                              76419EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!DeleteService                                                                               7641A07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!SetServiceObjectSecurity                                                                    76456CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!ChangeServiceConfigA                                                                        76456DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!ChangeServiceConfigW                                                                        76456F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!ChangeServiceConfig2A                                                                       76457099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!ChangeServiceConfig2W                                                                       764571E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] ADVAPI32.dll!CreateServiceA                                                                              764572A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] USER32.dll!SetWindowsHookExA                                                                             77636322 5 Bytes  JMP 000C0600 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] USER32.dll!SetWindowsHookExW                                                                             776387AD 5 Bytes  JMP 000C0804 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] USER32.dll!UnhookWindowsHookEx                                                                           776398DB 5 Bytes  JMP 000C0A08 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] USER32.dll!SetWinEventHook                                                                               77639F3A 5 Bytes  JMP 000C01F8 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4980] USER32.dll!UnhookWinEvent                                                                                7763C06F 5 Bytes  JMP 000C03FC 
.text           C:\Windows\system32\svchost.exe[5040] ntdll.dll!LdrLoadDll                                                                                           77D59378 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\svchost.exe[5040] ntdll.dll!LdrUnloadDll                                                                                         77D6B680 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\svchost.exe[5040] KERNEL32.dll!GetBinaryTypeW + 70                                                                               774F2247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!CreateServiceW                                                                                    76419EB4 5 Bytes  JMP 000803FC 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!DeleteService                                                                                     7641A07E 5 Bytes  JMP 00080600 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!SetServiceObjectSecurity                                                                          76456CD9 5 Bytes  JMP 00081014 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!ChangeServiceConfigA                                                                              76456DD9 5 Bytes  JMP 00080804 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!ChangeServiceConfigW                                                                              76456F81 5 Bytes  JMP 00080A08 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!ChangeServiceConfig2A                                                                             76457099 5 Bytes  JMP 00080C0C 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!ChangeServiceConfig2W                                                                             764571E1 5 Bytes  JMP 00080E10 
.text           C:\Windows\system32\svchost.exe[5040] ADVAPI32.dll!CreateServiceA                                                                                    764572A1 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\svchost.exe[5040] USER32.dll!SetWindowsHookExA                                                                                   77636322 5 Bytes  JMP 00090600 
.text           C:\Windows\system32\svchost.exe[5040] USER32.dll!SetWindowsHookExW                                                                                   776387AD 5 Bytes  JMP 00090804 
.text           C:\Windows\system32\svchost.exe[5040] USER32.dll!UnhookWindowsHookEx                                                                                 776398DB 5 Bytes  JMP 00090A08 
.text           C:\Windows\system32\svchost.exe[5040] USER32.dll!SetWinEventHook                                                                                     77639F3A 5 Bytes  JMP 000901F8 
.text           C:\Windows\system32\svchost.exe[5040] USER32.dll!UnhookWinEvent                                                                                      7763C06F 5 Bytes  JMP 000903FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ntdll.dll!LdrLoadDll                                                             77D59378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ntdll.dll!LdrUnloadDll                                                           77D6B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] KERNEL32.dll!GetBinaryTypeW + 70                                                 774F2247 1 Byte  [62]
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] USER32.dll!SetWindowsHookExA                                                     77636322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] USER32.dll!SetWindowsHookExW                                                     776387AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] USER32.dll!UnhookWindowsHookEx                                                   776398DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] USER32.dll!SetWinEventHook                                                       77639F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] USER32.dll!UnhookWinEvent                                                        7763C06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!CreateServiceW                                                      76419EB4 5 Bytes  JMP 001903FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!DeleteService                                                       7641A07E 5 Bytes  JMP 00190600 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!SetServiceObjectSecurity                                            76456CD9 5 Bytes  JMP 00191014 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!ChangeServiceConfigA                                                76456DD9 5 Bytes  JMP 00190804 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!ChangeServiceConfigW                                                76456F81 5 Bytes  JMP 00190A08 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!ChangeServiceConfig2A                                               76457099 5 Bytes  JMP 00190C0C 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!ChangeServiceConfig2W                                               764571E1 5 Bytes  JMP 00190E10 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] ADVAPI32.dll!CreateServiceA                                                      764572A1 5 Bytes  JMP 001901F8 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ntdll.dll!LdrLoadDll                                                     77D59378 5 Bytes  JMP 000501F8 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ntdll.dll!LdrUnloadDll                                                   77D6B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] KERNEL32.dll!GetBinaryTypeW + 70                                         774F2247 1 Byte  [62]
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!CreateServiceW                                              76419EB4 5 Bytes  JMP 000603FC 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!DeleteService                                               7641A07E 5 Bytes  JMP 00060600 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!SetServiceObjectSecurity                                    76456CD9 5 Bytes  JMP 00061014 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!ChangeServiceConfigA                                        76456DD9 5 Bytes  JMP 00060804 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!ChangeServiceConfigW                                        76456F81 5 Bytes  JMP 00060A08 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!ChangeServiceConfig2A                                       76457099 3 Bytes  JMP 00060C0C 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!ChangeServiceConfig2A + 4                                   7645709D 1 Byte  [89]
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!ChangeServiceConfig2W                                       764571E1 5 Bytes  JMP 00060E10 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] ADVAPI32.dll!CreateServiceA                                              764572A1 5 Bytes  JMP 000601F8 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] USER32.dll!SetWindowsHookExA                                             77636322 5 Bytes  JMP 000B0600 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] USER32.dll!SetWindowsHookExW                                             776387AD 5 Bytes  JMP 000B0804 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] USER32.dll!UnhookWindowsHookEx                                           776398DB 5 Bytes  JMP 000B0A08 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] USER32.dll!SetWinEventHook                                               77639F3A 5 Bytes  JMP 000B01F8 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5580] USER32.dll!UnhookWinEvent                                                7763C06F 5 Bytes  JMP 000B03FC 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ntdll.dll!LdrLoadDll                                                               77D59378 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ntdll.dll!LdrUnloadDll                                                             77D6B680 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] KERNEL32.dll!GetBinaryTypeW + 70                                                   774F2247 1 Byte  [62]
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!CreateServiceW                                                        76419EB4 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!DeleteService                                                         7641A07E 5 Bytes  JMP 00060600 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!SetServiceObjectSecurity                                              76456CD9 5 Bytes  JMP 00061014 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!ChangeServiceConfigA                                                  76456DD9 5 Bytes  JMP 00060804 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!ChangeServiceConfigW                                                  76456F81 5 Bytes  JMP 00060A08 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!ChangeServiceConfig2A                                                 76457099 3 Bytes  JMP 00060C0C 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!ChangeServiceConfig2A + 4                                             7645709D 1 Byte  [89]
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!ChangeServiceConfig2W                                                 764571E1 5 Bytes  JMP 00060E10 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] ADVAPI32.dll!CreateServiceA                                                        764572A1 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] USER32.dll!SetWindowsHookExA                                                       77636322 5 Bytes  JMP 00080600 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] USER32.dll!SetWindowsHookExW                                                       776387AD 5 Bytes  JMP 00080804 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] USER32.dll!UnhookWindowsHookEx                                                     776398DB 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] USER32.dll!SetWinEventHook                                                         77639F3A 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[5832] USER32.dll!UnhookWinEvent                                                          7763C06F 5 Bytes  JMP 000803FC 

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                          [00352EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                               [00352C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                 [00352C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[276] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                     [00352C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\system32\services.exe[696] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]                                         00060002
IAT             C:\Windows\system32\services.exe[696] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW]                                               00060000
IAT             C:\Program Files\Unlocker\UnlockerAssistant.exe[976] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                     [00312EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Unlocker\UnlockerAssistant.exe[976] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                          [00312C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Unlocker\UnlockerAssistant.exe[976] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                            [00312C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Unlocker\UnlockerAssistant.exe[976] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                [00312C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                       [00B82EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                            [00B82C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]              [00B82C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[1264] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                  [00B82C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\hkcmd.exe[1304] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                                      [003E2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\hkcmd.exe[1304] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                           [003E2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\hkcmd.exe[1304] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                             [003E2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\hkcmd.exe[1304] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                                 [003E2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1820] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                             [7390F6D0] C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll (Common functions/AVAST Software)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                                [74AD7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                                 [74B1B4E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                             [74ADBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                       [74ACF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                                 [74AD75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                              [74ACE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                                  [74B073F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                                     [74ADDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                             [74ACFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                              [74ACFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                               [74AC71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                                       [74B5CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                          [74AFC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                             [74ACD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                       [74AC6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                      [74AC687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                         [74AD2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                            [02552EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                                                                 [02552C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                                   [02552C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Explorer.EXE[1968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                       [02552C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxpers.exe[2252] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                                   [008C2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxpers.exe[2252] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                        [008C2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxpers.exe[2252] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                          [008C2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxpers.exe[2252] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                              [008C2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Winamp\winampa.exe[2480] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                                [00142EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Winamp\winampa.exe[2480] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                     [00142C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Winamp\winampa.exe[2480] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                       [00142C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Winamp\winampa.exe[2480] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                           [00142C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]           [00952EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                [00952C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]  [00952C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2524] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]      [00952C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                      [016A2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                           [016A2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]             [016A2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[2616] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                 [016A2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                [01C12EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                     [01C12C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                       [01C12C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2784] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                           [01C12C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3108] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                       [00112EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3108] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                            [00112C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3108] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                              [00112C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3108] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                  [00112C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                              [00822EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                   [00822C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                     [00822C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Real\RealPlayer\Update\realsched.exe[3120] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                         [00822C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                             [00A22EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                  [00A22C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                    [00A22C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Samsung\PanelMgr\SSMMgr.exe[3228] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                        [00A22C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Defender\MSASCui.exe[3324] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                      [00352EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Defender\MSASCui.exe[3324] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                           [00352C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Defender\MSASCui.exe[3324] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                             [00352C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Defender\MSASCui.exe[3324] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                 [00352C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                  [01992EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                       [01992C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                         [01992C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[3404] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                             [01992C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                 [00202EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                      [00202C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                        [00202C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[3556] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                            [00202C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Alwil Software\Avast5\AvastUI.exe[3600] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                              [7390F6D0] C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll (Common functions/AVAST Software)
IAT             C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                   [00182EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                        [00182C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                          [00182C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3612] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                              [00182C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\rundll32.exe[3724] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                                   [001A2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\rundll32.exe[3724] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                        [001A2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\rundll32.exe[3724] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                          [001A2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\rundll32.exe[3724] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                              [001A2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                      [01B52EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                           [01B52C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                             [01B52C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3776] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                 [01B52C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                         [00A12EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                              [00A12C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                [00A12C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Java\Java Update\jusched.exe[3800] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                    [00A12C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\RtHDVCpl.exe[3860] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                                            [003D2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\RtHDVCpl.exe[3860] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                                 [003D2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\RtHDVCpl.exe[3860] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                                   [003D2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\RtHDVCpl.exe[3860] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                                       [003D2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                      [01AF2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                           [01AF2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]             [01AF2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3888] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                 [01AF2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxtray.exe[3920] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                                   [00482EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxtray.exe[3920] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                        [00482C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxtray.exe[3920] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                          [00482C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\System32\igfxtray.exe[3920] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                              [00482C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                    [00942EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                         [00942C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                           [00942C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3944] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                               [00942C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                      [01852EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                           [01852C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]             [01852C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4436] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                 [01852C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                                            [001D2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                                                 [001D2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                                   [001D2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\ivilkeh3.exe[4676] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                                       [001D2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                      [00592EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose]                           [00592C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]             [00592C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[5272] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                 [00592C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                                               aswSP.SYS (avast! self protection module/AVAST Software)
Device          \FileSystem\fastfat \FatCdrom                                                                                                                        aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                                                                              Wdf01000.sys (Dynamiczna struktura WDF/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                                                                              Wdf01000.sys (Dynamiczna struktura WDF/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                              aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                              aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device          \FileSystem\fastfat \Fat                                                                                                                             aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                             fltmgr.sys (Menedżer filtrów systemu plików firmy Microsoft/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex@LogName                                                                            C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy543.gthr

---- EOF - GMER 1.0.15 ----
