GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-10 14:32:26
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK1032GSX rev.AS022M
Running: 4ki9svdy.exe; Driver: C:\Users\Rumianek\AppData\Local\Temp\kgrdikod.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwAddBootEntry [0x8DC18DF8]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ZwAllocateVirtualMemory [0x8DE66A5A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwAssignProcessToJobObject [0x8DC1985E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateEvent [0x8DC1E2E4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateEventPair [0x8DC1E330]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateIoCompletion [0x8DC1E422]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateMutant [0x8DC1E252]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateSection [0x8DC1E374]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateSemaphore [0x8DC1E29A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwCreateTimer [0x8DC1E3DC]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwDeleteBootEntry [0x8DC18E44]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ZwFreeVirtualMemory [0x8DE66B34]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwLoadDriver [0x8DC18AD6]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwModifyBootEntry [0x8DC18E90]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwNotifyChangeKey [0x8DC1BD1C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwNotifyChangeMultipleKeys [0x8DC19B02]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenEvent [0x8DC1E30E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenEventPair [0x8DC1E352]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenIoCompletion [0x8DC1E446]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenMutant [0x8DC1E278]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenSection [0x8DC1E3AE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenSemaphore [0x8DC1E2C2]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwOpenTimer [0x8DC1E400]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ZwProtectVirtualMemory [0x8DE66CA0]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwQueryObject [0x8DC199CE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwSetBootEntryOrder [0x8DC18EDC]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwSetBootOptions [0x8DC18F28]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwSetSystemInformation [0x8DC18B46]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwSetSystemPowerState [0x8DC18CEA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwShutdownSystem [0x8DC18C92]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwSystemDebugControl [0x8DC18D5A]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ZwTerminateProcess [0x8DE66D60]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                     ZwVdmControl [0x8DC18F74]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ZwWriteVirtualMemory [0x8DE66BE0]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ZwCreateProcessEx [0x8DE7CD92]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                     ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text           ntoskrnl.exe!KeInsertQueue + 2FD                                                                                                          828B18F4 4 Bytes  [F8, 8D, C1, 8D]
.text           ntoskrnl.exe!KeInsertQueue + 321                                                                                                          828B1918 4 Bytes  [5A, 6A, E6, 8D]
.text           ntoskrnl.exe!KeInsertQueue + 381                                                                                                          828B1978 4 Bytes  [5E, 98, C1, 8D]
.text           ntoskrnl.exe!KeInsertQueue + 3C1                                                                                                          828B19B8 8 Bytes  [E4, E2, C1, 8D, 30, E3, C1, ...]
.text           ntoskrnl.exe!KeInsertQueue + 3CD                                                                                                          828B19C4 4 Bytes  [22, E4, C1, 8D]
.text           ...                                                                                                                                       
PAGE            ntoskrnl.exe!ObMakeTemporaryObject                                                                                                        829E7E46 5 Bytes  JMP 8DE79C8C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntoskrnl.exe!ZwReplyWaitReceivePortEx + 110                                                                                               82A3154F 4 Bytes  CALL 8DC1A1B5 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            ntoskrnl.exe!ObInsertObject                                                                                                               82A35A1C 5 Bytes  JMP 8DE7B74C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntoskrnl.exe!ZwAlpcSendWaitReceivePort + 121                                                                                              82A5F013 4 Bytes  CALL 8DC1A1CB \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            ntoskrnl.exe!ZwCreateProcessEx                                                                                                            82ACCE84 7 Bytes  JMP 8DE7CD96 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text           win32k.sys!EngCreateRectRgn + 4537                                                                                                        9505FC70 5 Bytes  JMP 8DC1C67C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngEraseSurface + 104A                                                                                                         9506FE7E 5 Bytes  JMP 8DC1C70C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreatePalette + C20                                                                                                         95078ED9 5 Bytes  JMP 8DC1D2EA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngTransparentBlt + 4A1                                                                                                        95079CC5 5 Bytes  JMP 8DC1D450 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngTransparentBlt + 8C03                                                                                                       95082427 5 Bytes  JMP 8DC1BD52 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XLATEOBJ_iXlate + 616                                                                                                          9508337E 5 Bytes  JMP 8DC1D0BA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XFORMOBJ_iGetXform + 30F6                                                                                                      9508EAB7 5 Bytes  JMP 8DC1C536 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XFORMOBJ_iGetXform + 4569                                                                                                      9508FF2A 5 Bytes  JMP 8DC1BF84 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XFORMOBJ_iGetXform + 46B8                                                                                                      95090079 5 Bytes  JMP 8DC1C7E6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XFORMOBJ_iGetXform + 4C4D                                                                                                      9509060E 5 Bytes  JMP 8DC1C7FE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngMapFontFileFD + 119EE                                                                                                       950A9A85 5 Bytes  JMP 8DC1C384 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngMapFontFileFD + 11A42                                                                                                       950A9AD9 5 Bytes  JMP 8DC1C562 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngGradientFill + 377F                                                                                                         950D0ABE 5 Bytes  JMP 8DC1CF8C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngGradientFill + 60DE                                                                                                         950D341D 5 Bytes  JMP 8DC1BE4E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngMulDiv + 4D3F                                                                                                               950D9D6E 5 Bytes  JMP 8DC1BFF4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngStretchBlt + 2B42                                                                                                           950E420C 5 Bytes  JMP 8DC1D4F2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngStrokePath + 5FF                                                                                                            950E70F4 5 Bytes  JMP 8DC1BE66 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngLpkInstalled + 1D73                                                                                                         950F0F17 5 Bytes  JMP 8DC1D07C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngAlphaBlend + B948                                                                                                           95101475 5 Bytes  JMP 8DC1C724 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngNineGrid + 8C4                                                                                                              95105667 5 Bytes  JMP 8DC1D232 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngNineGrid + 6F60                                                                                                             9510BD03 5 Bytes  JMP 8DC1D036 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCopyBits + B0F                                                                                                              9510F48A 5 Bytes  JMP 8DC1D180 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!STROBJ_vEnumStart + 4728                                                                                                       95116DA9 5 Bytes  JMP 8DC1BF22 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngDeleteSemaphore + E80                                                                                                       95135344 5 Bytes  JMP 8DC1C1AC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!CLIPOBJ_bEnum + 248                                                                                                            9513ABC2 5 Bytes  JMP 8DC1C0B0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngPlgBlt + 26D9                                                                                                               9513E6FA 5 Bytes  JMP 8DC1D3A8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngFillPath + 375D                                                                                                             95156AC4 5 Bytes  JMP 8DC1C73C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngLineTo + A0F                                                                                                                9515CC07 5 Bytes  JMP 8DC1C104 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngLineTo + D249                                                                                                               95169441 5 Bytes  JMP 8DC1C2E4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngLineTo + 10CBA                                                                                                              9516CEB2 5 Bytes  JMP 8DC1C248 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)

---- User code sections - GMER 1.0.15 ----

.text           C:\Windows\system32\taskeng.exe[512] ntdll.dll!LdrLoadDll                                                                                 772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\taskeng.exe[512] ntdll.dll!LdrUnloadDll                                                                               7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\taskeng.exe[512] kernel32.dll!GetBinaryTypeW + 70                                                                     76242247 1 Byte  [62]
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!CreateServiceW                                                                          770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!DeleteService                                                                           770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!SetServiceObjectSecurity                                                                77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!ChangeServiceConfigA                                                                    77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!ChangeServiceConfigW                                                                    77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!ChangeServiceConfig2A                                                                   77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!ChangeServiceConfig2W                                                                   771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\taskeng.exe[512] ADVAPI32.dll!CreateServiceA                                                                          771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\taskeng.exe[512] USER32.dll!SetWindowsHookExA                                                                         75ED6322 5 Bytes  JMP 00090600 
.text           C:\Windows\system32\taskeng.exe[512] USER32.dll!SetWindowsHookExW                                                                         75ED87AD 5 Bytes  JMP 00090804 
.text           C:\Windows\system32\taskeng.exe[512] USER32.dll!UnhookWindowsHookEx                                                                       75ED98DB 5 Bytes  JMP 00090A08 
.text           C:\Windows\system32\taskeng.exe[512] USER32.dll!SetWinEventHook                                                                           75ED9F3A 5 Bytes  JMP 000901F8 
.text           C:\Windows\system32\taskeng.exe[512] USER32.dll!UnhookWinEvent                                                                            75EDC06F 5 Bytes  JMP 000903FC 
.text           C:\Windows\system32\csrss.exe[548] KERNEL32.dll!GetBinaryTypeW + 70                                                                       76242247 1 Byte  [62]
.text           C:\Windows\system32\wininit.exe[592] ntdll.dll!LdrLoadDll                                                                                 772F9378 5 Bytes  JMP 000301F8 
.text           C:\Windows\system32\wininit.exe[592] ntdll.dll!LdrUnloadDll                                                                               7730B680 5 Bytes  JMP 000303FC 
.text           C:\Windows\system32\wininit.exe[592] kernel32.dll!GetBinaryTypeW + 70                                                                     76242247 1 Byte  [62]
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!CreateServiceW                                                                          770F9EB4 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!DeleteService                                                                           770FA07E 5 Bytes  JMP 00050600 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!SetServiceObjectSecurity                                                                77136CD9 5 Bytes  JMP 00051014 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigA                                                                    77136DD9 5 Bytes  JMP 00050804 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfigW                                                                    77136F81 5 Bytes  JMP 00050A08 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfig2A                                                                   77137099 5 Bytes  JMP 00050C0C 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!ChangeServiceConfig2W                                                                   771371E1 5 Bytes  JMP 00050E10 
.text           C:\Windows\system32\wininit.exe[592] ADVAPI32.dll!CreateServiceA                                                                          771372A1 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExA                                                                         75ED6322 5 Bytes  JMP 00060600 
.text           C:\Windows\system32\wininit.exe[592] USER32.dll!SetWindowsHookExW                                                                         75ED87AD 5 Bytes  JMP 00060804 
.text           C:\Windows\system32\wininit.exe[592] USER32.dll!UnhookWindowsHookEx                                                                       75ED98DB 5 Bytes  JMP 00060A08 
.text           C:\Windows\system32\wininit.exe[592] USER32.dll!SetWinEventHook                                                                           75ED9F3A 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\wininit.exe[592] USER32.dll!UnhookWinEvent                                                                            75EDC06F 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\csrss.exe[604] KERNEL32.dll!GetBinaryTypeW + 70                                                                       76242247 1 Byte  [62]
.text           C:\Windows\system32\services.exe[636] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000A01F8 
.text           C:\Windows\system32\services.exe[636] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000A03FC 
.text           C:\Windows\system32\services.exe[636] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000D03FC 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 000D0600 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 000D1014 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 000D0804 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 000D0A08 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 000D0C0C 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 000D0E10 
.text           C:\Windows\system32\services.exe[636] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000D01F8 
.text           C:\Windows\system32\services.exe[636] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 000E0600 
.text           C:\Windows\system32\services.exe[636] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 000E0804 
.text           C:\Windows\system32\services.exe[636] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 000E0A08 
.text           C:\Windows\system32\services.exe[636] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 000E01F8 
.text           C:\Windows\system32\services.exe[636] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 000E03FC 
.text           C:\Windows\system32\lsass.exe[648] ntdll.dll!LdrLoadDll                                                                                   772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\lsass.exe[648] ntdll.dll!LdrUnloadDll                                                                                 7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\lsass.exe[648] kernel32.dll!GetBinaryTypeW + 70                                                                       76242247 1 Byte  [62]
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!CreateServiceW                                                                            770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!DeleteService                                                                             770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!SetServiceObjectSecurity                                                                  77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfigA                                                                      77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfigW                                                                      77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfig2A                                                                     77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!ChangeServiceConfig2W                                                                     771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\lsass.exe[648] ADVAPI32.dll!CreateServiceA                                                                            771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\lsass.exe[648] USER32.dll!SetWindowsHookExA                                                                           75ED6322 5 Bytes  JMP 00080600 
.text           C:\Windows\system32\lsass.exe[648] USER32.dll!SetWindowsHookExW                                                                           75ED87AD 5 Bytes  JMP 00080804 
.text           C:\Windows\system32\lsass.exe[648] USER32.dll!UnhookWindowsHookEx                                                                         75ED98DB 5 Bytes  JMP 00080A08 
.text           C:\Windows\system32\lsass.exe[648] USER32.dll!SetWinEventHook                                                                             75ED9F3A 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\lsass.exe[648] USER32.dll!UnhookWinEvent                                                                              75EDC06F 5 Bytes  JMP 000803FC 
.text           C:\Windows\system32\lsm.exe[660] ntdll.dll!LdrLoadDll                                                                                     772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\lsm.exe[660] ntdll.dll!LdrUnloadDll                                                                                   7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\lsm.exe[660] kernel32.dll!GetBinaryTypeW + 70                                                                         76242247 1 Byte  [62]
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!CreateServiceW                                                                              770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!DeleteService                                                                               770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!SetServiceObjectSecurity                                                                    77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!ChangeServiceConfigA                                                                        77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!ChangeServiceConfigW                                                                        77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!ChangeServiceConfig2A                                                                       77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!ChangeServiceConfig2W                                                                       771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\lsm.exe[660] ADVAPI32.dll!CreateServiceA                                                                              771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\winlogon.exe[740] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000301F8 
.text           C:\Windows\system32\winlogon.exe[740] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000303FC 
.text           C:\Windows\system32\winlogon.exe[740] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00050600 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00051014 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00050804 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00050A08 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00050C0C 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00050E10 
.text           C:\Windows\system32\winlogon.exe[740] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\winlogon.exe[740] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00060600 
.text           C:\Windows\system32\winlogon.exe[740] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00060804 
.text           C:\Windows\system32\winlogon.exe[740] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00060A08 
.text           C:\Windows\system32\winlogon.exe[740] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 000601F8 
.text           C:\Windows\system32\winlogon.exe[740] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 000603FC 
.text           C:\Windows\system32\svchost.exe[848] ntdll.dll!LdrLoadDll                                                                                 772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[848] ntdll.dll!LdrUnloadDll                                                                               7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[848] kernel32.dll!GetBinaryTypeW + 70                                                                     76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!CreateServiceW                                                                          770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!DeleteService                                                                           770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!SetServiceObjectSecurity                                                                77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfigA                                                                    77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfigW                                                                    77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfig2A                                                                   77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!ChangeServiceConfig2W                                                                   771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[848] ADVAPI32.dll!CreateServiceA                                                                          771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[848] USER32.dll!SetWindowsHookExA                                                                         75ED6322 5 Bytes  JMP 00270600 
.text           C:\Windows\system32\svchost.exe[848] USER32.dll!SetWindowsHookExW                                                                         75ED87AD 5 Bytes  JMP 00270804 
.text           C:\Windows\system32\svchost.exe[848] USER32.dll!UnhookWindowsHookEx                                                                       75ED98DB 5 Bytes  JMP 00270A08 
.text           C:\Windows\system32\svchost.exe[848] USER32.dll!SetWinEventHook                                                                           75ED9F3A 5 Bytes  JMP 002701F8 
.text           C:\Windows\system32\svchost.exe[848] USER32.dll!UnhookWinEvent                                                                            75EDC06F 5 Bytes  JMP 002703FC 
.text           C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrLoadDll                                                                                 772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[920] ntdll.dll!LdrUnloadDll                                                                               7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[920] kernel32.dll!GetBinaryTypeW + 70                                                                     76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!CreateServiceW                                                                          770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!DeleteService                                                                           770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!SetServiceObjectSecurity                                                                77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfigA                                                                    77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfigW                                                                    77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfig2A                                                                   77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!ChangeServiceConfig2W                                                                   771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!CreateServiceA                                                                          771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExA                                                                         75ED6322 5 Bytes  JMP 00250600 
.text           C:\Windows\system32\svchost.exe[920] USER32.dll!SetWindowsHookExW                                                                         75ED87AD 5 Bytes  JMP 00250804 
.text           C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWindowsHookEx                                                                       75ED98DB 5 Bytes  JMP 00250A08 
.text           C:\Windows\system32\svchost.exe[920] USER32.dll!SetWinEventHook                                                                           75ED9F3A 5 Bytes  JMP 002501F8 
.text           C:\Windows\system32\svchost.exe[920] USER32.dll!UnhookWinEvent                                                                            75EDC06F 5 Bytes  JMP 002503FC 
.text           C:\Windows\System32\svchost.exe[956] ntdll.dll!LdrLoadDll                                                                                 772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\System32\svchost.exe[956] ntdll.dll!LdrUnloadDll                                                                               7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\System32\svchost.exe[956] kernel32.dll!GetBinaryTypeW + 70                                                                     76242247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!CreateServiceW                                                                          770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!DeleteService                                                                           770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!SetServiceObjectSecurity                                                                77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfigA                                                                    77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfigW                                                                    77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfig2A                                                                   77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!ChangeServiceConfig2W                                                                   771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!CreateServiceA                                                                          771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\System32\svchost.exe[956] USER32.dll!SetWindowsHookExA                                                                         75ED6322 5 Bytes  JMP 00A50600 
.text           C:\Windows\System32\svchost.exe[956] USER32.dll!SetWindowsHookExW                                                                         75ED87AD 5 Bytes  JMP 00A50804 
.text           C:\Windows\System32\svchost.exe[956] USER32.dll!UnhookWindowsHookEx                                                                       75ED98DB 5 Bytes  JMP 00A50A08 
.text           C:\Windows\System32\svchost.exe[956] USER32.dll!SetWinEventHook                                                                           75ED9F3A 5 Bytes  JMP 00A501F8 
.text           C:\Windows\System32\svchost.exe[956] USER32.dll!UnhookWinEvent                                                                            75EDC06F 5 Bytes  JMP 00A503FC 
.text           C:\Windows\System32\svchost.exe[1044] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000901F8 
.text           C:\Windows\System32\svchost.exe[1044] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000903FC 
.text           C:\Windows\System32\svchost.exe[1044] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000B03FC 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 000B0600 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 000B1014 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 000B0804 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 000B0A08 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 000B0C0C 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 000B0E10 
.text           C:\Windows\System32\svchost.exe[1044] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000B01F8 
.text           C:\Windows\System32\svchost.exe[1044] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00150600 
.text           C:\Windows\System32\svchost.exe[1044] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00150804 
.text           C:\Windows\System32\svchost.exe[1044] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00150A08 
.text           C:\Windows\System32\svchost.exe[1044] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 001501F8 
.text           C:\Windows\System32\svchost.exe[1044] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 001503FC 
.text           C:\Windows\System32\svchost.exe[1084] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\System32\svchost.exe[1084] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00D20600 
.text           C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00D20804 
.text           C:\Windows\System32\svchost.exe[1084] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00D20A08 
.text           C:\Windows\System32\svchost.exe[1084] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 00D201F8 
.text           C:\Windows\System32\svchost.exe[1084] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 00D203FC 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ntdll.dll!LdrLoadDll                                                     772F9378 5 Bytes  JMP 001501F8 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ntdll.dll!LdrUnloadDll                                                   7730B680 5 Bytes  JMP 001503FC 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] kernel32.dll!GetBinaryTypeW + 70                                         76242247 1 Byte  [62]
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] USER32.dll!SetWindowsHookExA                                             75ED6322 5 Bytes  JMP 00170600 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] USER32.dll!SetWindowsHookExW                                             75ED87AD 5 Bytes  JMP 00170804 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] USER32.dll!UnhookWindowsHookEx                                           75ED98DB 5 Bytes  JMP 00170A08 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] USER32.dll!SetWinEventHook                                               75ED9F3A 5 Bytes  JMP 001701F8 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] USER32.dll!UnhookWinEvent                                                75EDC06F 5 Bytes  JMP 001703FC 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!CreateServiceW                                              770F9EB4 5 Bytes  JMP 001803FC 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!DeleteService                                               770FA07E 5 Bytes  JMP 00180600 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!SetServiceObjectSecurity                                    77136CD9 5 Bytes  JMP 00181014 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!ChangeServiceConfigA                                        77136DD9 5 Bytes  JMP 00180804 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!ChangeServiceConfigW                                        77136F81 5 Bytes  JMP 00180A08 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!ChangeServiceConfig2A                                       77137099 5 Bytes  JMP 00180C0C 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!ChangeServiceConfig2W                                       771371E1 5 Bytes  JMP 00180E10 
.text           c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe[1096] ADVAPI32.dll!CreateServiceA                                              771372A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\system32\svchost.exe[1140] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[1140] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[1140] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00170600 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\system32\svchost.exe[1140] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00BF0600 
.text           C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00BF0804 
.text           C:\Windows\system32\svchost.exe[1140] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00BF0A08 
.text           C:\Windows\system32\svchost.exe[1140] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 00BF01F8 
.text           C:\Windows\system32\svchost.exe[1140] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 00BF03FC 
.text           C:\Windows\system32\AUDIODG.EXE[1216] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1240] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[1240] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[1288] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[1288] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[1288] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[1288] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00CA0600 
.text           C:\Windows\system32\svchost.exe[1288] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00CA0804 
.text           C:\Windows\system32\svchost.exe[1288] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00CA0A08 
.text           C:\Windows\system32\svchost.exe[1288] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 00CA01F8 
.text           C:\Windows\system32\svchost.exe[1288] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 00CA03FC 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ntdll.dll!LdrLoadDll                                                                  772F9378 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ntdll.dll!LdrUnloadDll                                                                7730B680 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] kernel32.dll!GetBinaryTypeW + 70                                                      76242247 1 Byte  [62]
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!CreateServiceW                                                           770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!DeleteService                                                            770FA07E 5 Bytes  JMP 00070600 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!SetServiceObjectSecurity                                                 77136CD9 5 Bytes  JMP 00071014 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!ChangeServiceConfigA                                                     77136DD9 5 Bytes  JMP 00070804 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!ChangeServiceConfigW                                                     77136F81 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!ChangeServiceConfig2A                                                    77137099 5 Bytes  JMP 00070C0C 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!ChangeServiceConfig2W                                                    771371E1 5 Bytes  JMP 00070E10 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] ADVAPI32.dll!CreateServiceA                                                           771372A1 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] USER32.dll!SetWindowsHookExA                                                          75ED6322 5 Bytes  JMP 00080600 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] USER32.dll!SetWindowsHookExW                                                          75ED87AD 5 Bytes  JMP 00080804 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] USER32.dll!UnhookWindowsHookEx                                                        75ED98DB 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] USER32.dll!SetWinEventHook                                                            75ED9F3A 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Windows Defender\MSASCui.exe[1336] USER32.dll!UnhookWinEvent                                                             75EDC06F 5 Bytes  JMP 000803FC 
.text           C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[1384] KERNEL32.dll!GetBinaryTypeW + 70                                                   76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ntdll.dll!LdrLoadDll                                                              772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ntdll.dll!LdrUnloadDll                                                            7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] kernel32.dll!GetBinaryTypeW + 70                                                  76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!CreateServiceW                                                       770F9EB4 5 Bytes  JMP 001A03FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!DeleteService                                                        770FA07E 5 Bytes  JMP 001A0600 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!SetServiceObjectSecurity                                             77136CD9 5 Bytes  JMP 001A1014 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!ChangeServiceConfigA                                                 77136DD9 5 Bytes  JMP 001A0804 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!ChangeServiceConfigW                                                 77136F81 5 Bytes  JMP 001A0A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!ChangeServiceConfig2A                                                77137099 5 Bytes  JMP 001A0C0C 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!ChangeServiceConfig2W                                                771371E1 5 Bytes  JMP 001A0E10 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] ADVAPI32.dll!CreateServiceA                                                       771372A1 5 Bytes  JMP 001A01F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] USER32.dll!SetWindowsHookExA                                                      75ED6322 5 Bytes  JMP 001B0600 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] USER32.dll!SetWindowsHookExW                                                      75ED87AD 5 Bytes  JMP 001B0804 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] USER32.dll!UnhookWindowsHookEx                                                    75ED98DB 5 Bytes  JMP 001B0A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] USER32.dll!SetWinEventHook                                                        75ED9F3A 5 Bytes  JMP 001B01F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[1408] USER32.dll!UnhookWinEvent                                                         75EDC06F 5 Bytes  JMP 001B03FC 
.text           C:\Windows\system32\svchost.exe[1476] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[1476] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[1476] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[1476] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[1476] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 000B0600 
.text           C:\Windows\system32\svchost.exe[1476] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 000B0804 
.text           C:\Windows\system32\svchost.exe[1476] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 000B0A08 
.text           C:\Windows\system32\svchost.exe[1476] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 000B01F8 
.text           C:\Windows\system32\svchost.exe[1476] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 000B03FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ntdll.dll!LdrLoadDll                                                             772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ntdll.dll!LdrUnloadDll                                                           7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] kernel32.dll!GetBinaryTypeW + 70                                                 76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] USER32.dll!SetWindowsHookExA                                                     75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] USER32.dll!SetWindowsHookExW                                                     75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] USER32.dll!UnhookWindowsHookEx                                                   75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] USER32.dll!SetWinEventHook                                                       75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] USER32.dll!UnhookWinEvent                                                        75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!CreateServiceW                                                      770F9EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!DeleteService                                                       770FA07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!SetServiceObjectSecurity                                            77136CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!ChangeServiceConfigA                                                77136DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!ChangeServiceConfigW                                                77136F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!ChangeServiceConfig2A                                               77137099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!ChangeServiceConfig2W                                               771371E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1492] ADVAPI32.dll!CreateServiceA                                                      771372A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\system32\taskeng.exe[1588] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\taskeng.exe[1588] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\taskeng.exe[1588] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\taskeng.exe[1588] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\taskeng.exe[1588] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00080600 
.text           C:\Windows\system32\taskeng.exe[1588] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00080804 
.text           C:\Windows\system32\taskeng.exe[1588] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00080A08 
.text           C:\Windows\system32\taskeng.exe[1588] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\taskeng.exe[1588] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1656] kernel32.dll!SetUnhandledExceptionFilter                                        7621A84F 4 Bytes  [C2, 04, 00, 90] {RET 0x4; NOP }
.text           C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1656] kernel32.dll!GetBinaryTypeW + 70                                                76242247 1 Byte  [62]
.text           C:\Windows\System32\spoolsv.exe[1836] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\System32\spoolsv.exe[1836] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\System32\spoolsv.exe[1836] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\System32\spoolsv.exe[1836] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\System32\spoolsv.exe[1836] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 001A0600 
.text           C:\Windows\System32\spoolsv.exe[1836] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 001A0804 
.text           C:\Windows\System32\spoolsv.exe[1836] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 001A0A08 
.text           C:\Windows\System32\spoolsv.exe[1836] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 001A01F8 
.text           C:\Windows\System32\spoolsv.exe[1836] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 001A03FC 
.text           C:\Windows\system32\svchost.exe[1860] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[1860] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[1860] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[1860] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00180600 
.text           C:\Windows\system32\svchost.exe[1860] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00180804 
.text           C:\Windows\system32\svchost.exe[1860] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00180A08 
.text           C:\Windows\system32\svchost.exe[1860] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 001801F8 
.text           C:\Windows\system32\svchost.exe[1860] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 001803FC 
.text           C:\Windows\system32\Dwm.exe[1932] ntdll.dll!LdrLoadDll                                                                                    772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\Dwm.exe[1932] ntdll.dll!LdrUnloadDll                                                                                  7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\Dwm.exe[1932] kernel32.dll!GetBinaryTypeW + 70                                                                        76242247 1 Byte  [62]
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!CreateServiceW                                                                             770F9EB4 5 Bytes  JMP 000803FC 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!DeleteService                                                                              770FA07E 5 Bytes  JMP 00080600 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!SetServiceObjectSecurity                                                                   77136CD9 5 Bytes  JMP 00081014 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!ChangeServiceConfigA                                                                       77136DD9 5 Bytes  JMP 00080804 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!ChangeServiceConfigW                                                                       77136F81 5 Bytes  JMP 00080A08 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!ChangeServiceConfig2A                                                                      77137099 5 Bytes  JMP 00080C0C 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!ChangeServiceConfig2W                                                                      771371E1 5 Bytes  JMP 00080E10 
.text           C:\Windows\system32\Dwm.exe[1932] ADVAPI32.dll!CreateServiceA                                                                             771372A1 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\Dwm.exe[1932] USER32.dll!SetWindowsHookExA                                                                            75ED6322 5 Bytes  JMP 00090600 
.text           C:\Windows\system32\Dwm.exe[1932] USER32.dll!SetWindowsHookExW                                                                            75ED87AD 5 Bytes  JMP 00090804 
.text           C:\Windows\system32\Dwm.exe[1932] USER32.dll!UnhookWindowsHookEx                                                                          75ED98DB 5 Bytes  JMP 00090A08 
.text           C:\Windows\system32\Dwm.exe[1932] USER32.dll!SetWinEventHook                                                                              75ED9F3A 5 Bytes  JMP 000901F8 
.text           C:\Windows\system32\Dwm.exe[1932] USER32.dll!UnhookWinEvent                                                                               75EDC06F 5 Bytes  JMP 000903FC 
.text           C:\Windows\Explorer.EXE[2024] ntdll.dll!LdrLoadDll                                                                                        772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\Explorer.EXE[2024] ntdll.dll!LdrUnloadDll                                                                                      7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\Explorer.EXE[2024] kernel32.dll!GetBinaryTypeW + 70                                                                            76242247 1 Byte  [62]
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!CreateServiceW                                                                                 770F9EB4 5 Bytes  JMP 000B03FC 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!DeleteService                                                                                  770FA07E 5 Bytes  JMP 000B0600 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!SetServiceObjectSecurity                                                                       77136CD9 5 Bytes  JMP 000B1014 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!ChangeServiceConfigA                                                                           77136DD9 5 Bytes  JMP 000B0804 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!ChangeServiceConfigW                                                                           77136F81 5 Bytes  JMP 000B0A08 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!ChangeServiceConfig2A                                                                          77137099 5 Bytes  JMP 000B0C0C 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!ChangeServiceConfig2W                                                                          771371E1 5 Bytes  JMP 000B0E10 
.text           C:\Windows\Explorer.EXE[2024] ADVAPI32.dll!CreateServiceA                                                                                 771372A1 5 Bytes  JMP 000B01F8 
.text           C:\Windows\Explorer.EXE[2024] USER32.dll!SetWindowsHookExA                                                                                75ED6322 5 Bytes  JMP 000C0600 
.text           C:\Windows\Explorer.EXE[2024] USER32.dll!SetWindowsHookExW                                                                                75ED87AD 5 Bytes  JMP 000C0804 
.text           C:\Windows\Explorer.EXE[2024] USER32.dll!UnhookWindowsHookEx                                                                              75ED98DB 5 Bytes  JMP 000C0A08 
.text           C:\Windows\Explorer.EXE[2024] USER32.dll!SetWinEventHook                                                                                  75ED9F3A 5 Bytes  JMP 000C01F8 
.text           C:\Windows\Explorer.EXE[2024] USER32.dll!UnhookWinEvent                                                                                   75EDC06F 5 Bytes  JMP 000C03FC 
.text           C:\Windows\Explorer.EXE[2024] SHELL32.dll!SHFileOperationW                                                                                763168E8 5 Bytes  JMP 10001102 C:\Program Files\Unlocker\UnlockerHook.dll
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ntdll.dll!LdrLoadDll                                                   772F9378 5 Bytes  JMP 001501F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ntdll.dll!LdrUnloadDll                                                 7730B680 5 Bytes  JMP 001503FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] kernel32.dll!GetBinaryTypeW + 70                                       76242247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] USER32.dll!SetWindowsHookExA                                           75ED6322 5 Bytes  JMP 003B0600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] USER32.dll!SetWindowsHookExW                                           75ED87AD 5 Bytes  JMP 003B0804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] USER32.dll!UnhookWindowsHookEx                                         75ED98DB 5 Bytes  JMP 003B0A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] USER32.dll!SetWinEventHook                                             75ED9F3A 5 Bytes  JMP 003B01F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] USER32.dll!UnhookWinEvent                                              75EDC06F 5 Bytes  JMP 003B03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!CreateServiceW                                            770F9EB4 5 Bytes  JMP 003C03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!DeleteService                                             770FA07E 5 Bytes  JMP 003C0600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!SetServiceObjectSecurity                                  77136CD9 5 Bytes  JMP 003C1014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!ChangeServiceConfigA                                      77136DD9 5 Bytes  JMP 003C0804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!ChangeServiceConfigW                                      77136F81 5 Bytes  JMP 003C0A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!ChangeServiceConfig2A                                     77137099 5 Bytes  JMP 003C0C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!ChangeServiceConfig2W                                     771371E1 5 Bytes  JMP 003C0E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] ADVAPI32.dll!CreateServiceA                                            771372A1 5 Bytes  JMP 003C01F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ntdll.dll!LdrLoadDll                                                                  772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ntdll.dll!LdrUnloadDll                                                                7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] kernel32.dll!GetBinaryTypeW + 70                                                      76242247 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] USER32.dll!SetWindowsHookExA                                                          75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] USER32.dll!SetWindowsHookExW                                                          75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] USER32.dll!UnhookWindowsHookEx                                                        75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] USER32.dll!SetWinEventHook                                                            75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] USER32.dll!UnhookWinEvent                                                             75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!CreateServiceW                                                           770F9EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!DeleteService                                                            770FA07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!SetServiceObjectSecurity                                                 77136CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!ChangeServiceConfigA                                                     77136DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!ChangeServiceConfigW                                                     77136F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!ChangeServiceConfig2A                                                    77137099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!ChangeServiceConfig2W                                                    771371E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2292] ADVAPI32.dll!CreateServiceA                                                           771372A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\RtHDVCpl.exe[2308] ntdll.dll!LdrLoadDll                                                                                        772F9378 5 Bytes  JMP 001501F8 
.text           C:\Windows\RtHDVCpl.exe[2308] ntdll.dll!LdrUnloadDll                                                                                      7730B680 5 Bytes  JMP 001503FC 
.text           C:\Windows\RtHDVCpl.exe[2308] kernel32.dll!GetBinaryTypeW + 70                                                                            76242247 1 Byte  [62]
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!CreateServiceW                                                                                 770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!DeleteService                                                                                  770FA07E 5 Bytes  JMP 00170600 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!SetServiceObjectSecurity                                                                       77136CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!ChangeServiceConfigA                                                                           77136DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!ChangeServiceConfigW                                                                           77136F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!ChangeServiceConfig2A                                                                          77137099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!ChangeServiceConfig2W                                                                          771371E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\RtHDVCpl.exe[2308] ADVAPI32.dll!CreateServiceA                                                                                 771372A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\RtHDVCpl.exe[2308] USER32.dll!SetWindowsHookExA                                                                                75ED6322 5 Bytes  JMP 00180600 
.text           C:\Windows\RtHDVCpl.exe[2308] USER32.dll!SetWindowsHookExW                                                                                75ED87AD 5 Bytes  JMP 00180804 
.text           C:\Windows\RtHDVCpl.exe[2308] USER32.dll!UnhookWindowsHookEx                                                                              75ED98DB 5 Bytes  JMP 00180A08 
.text           C:\Windows\RtHDVCpl.exe[2308] USER32.dll!SetWinEventHook                                                                                  75ED9F3A 5 Bytes  JMP 001801F8 
.text           C:\Windows\RtHDVCpl.exe[2308] USER32.dll!UnhookWinEvent                                                                                   75EDC06F 5 Bytes  JMP 001803FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ntdll.dll!LdrLoadDll                                                                772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ntdll.dll!LdrUnloadDll                                                              7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] kernel32.dll!GetBinaryTypeW + 70                                                    76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] USER32.dll!SetWindowsHookExA                                                        75ED6322 5 Bytes  JMP 002C0600 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] USER32.dll!SetWindowsHookExW                                                        75ED87AD 5 Bytes  JMP 002C0804 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] USER32.dll!UnhookWindowsHookEx                                                      75ED98DB 5 Bytes  JMP 002C0A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] USER32.dll!SetWinEventHook                                                          75ED9F3A 5 Bytes  JMP 002C01F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] USER32.dll!UnhookWinEvent                                                           75EDC06F 5 Bytes  JMP 002C03FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!CreateServiceW                                                         770F9EB4 5 Bytes  JMP 003D03FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!DeleteService                                                          770FA07E 5 Bytes  JMP 003D0600 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!SetServiceObjectSecurity                                               77136CD9 5 Bytes  JMP 003D1014 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!ChangeServiceConfigA                                                   77136DD9 5 Bytes  JMP 003D0804 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!ChangeServiceConfigW                                                   77136F81 5 Bytes  JMP 003D0A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!ChangeServiceConfig2A                                                  77137099 5 Bytes  JMP 003D0C0C 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!ChangeServiceConfig2W                                                  771371E1 5 Bytes  JMP 003D0E10 
.text           C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe[2328] ADVAPI32.dll!CreateServiceA                                                         771372A1 5 Bytes  JMP 003D01F8 
.text           C:\Windows\System32\igfxtray.exe[2344] ntdll.dll!LdrLoadDll                                                                               772F9378 5 Bytes  JMP 001401F8 
.text           C:\Windows\System32\igfxtray.exe[2344] ntdll.dll!LdrUnloadDll                                                                             7730B680 5 Bytes  JMP 001403FC 
.text           C:\Windows\System32\igfxtray.exe[2344] kernel32.dll!GetBinaryTypeW + 70                                                                   76242247 1 Byte  [62]
.text           C:\Windows\System32\igfxtray.exe[2344] USER32.dll!SetWindowsHookExA                                                                       75ED6322 5 Bytes  JMP 00160600 
.text           C:\Windows\System32\igfxtray.exe[2344] USER32.dll!SetWindowsHookExW                                                                       75ED87AD 5 Bytes  JMP 00160804 
.text           C:\Windows\System32\igfxtray.exe[2344] USER32.dll!UnhookWindowsHookEx                                                                     75ED98DB 5 Bytes  JMP 00160A08 
.text           C:\Windows\System32\igfxtray.exe[2344] USER32.dll!SetWinEventHook                                                                         75ED9F3A 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\igfxtray.exe[2344] USER32.dll!UnhookWinEvent                                                                          75EDC06F 5 Bytes  JMP 001603FC 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!CreateServiceW                                                                        770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!DeleteService                                                                         770FA07E 5 Bytes  JMP 00170600 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!SetServiceObjectSecurity                                                              77136CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!ChangeServiceConfigA                                                                  77136DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!ChangeServiceConfigW                                                                  77136F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!ChangeServiceConfig2A                                                                 77137099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!ChangeServiceConfig2W                                                                 771371E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\System32\igfxtray.exe[2344] ADVAPI32.dll!CreateServiceA                                                                        771372A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\System32\hkcmd.exe[2356] ntdll.dll!LdrLoadDll                                                                                  772F9378 5 Bytes  JMP 001401F8 
.text           C:\Windows\System32\hkcmd.exe[2356] ntdll.dll!LdrUnloadDll                                                                                7730B680 5 Bytes  JMP 001403FC 
.text           C:\Windows\System32\hkcmd.exe[2356] kernel32.dll!GetBinaryTypeW + 70                                                                      76242247 1 Byte  [62]
.text           C:\Windows\System32\hkcmd.exe[2356] USER32.dll!SetWindowsHookExA                                                                          75ED6322 5 Bytes  JMP 00160600 
.text           C:\Windows\System32\hkcmd.exe[2356] USER32.dll!SetWindowsHookExW                                                                          75ED87AD 5 Bytes  JMP 00160804 
.text           C:\Windows\System32\hkcmd.exe[2356] USER32.dll!UnhookWindowsHookEx                                                                        75ED98DB 5 Bytes  JMP 00160A08 
.text           C:\Windows\System32\hkcmd.exe[2356] USER32.dll!SetWinEventHook                                                                            75ED9F3A 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\hkcmd.exe[2356] USER32.dll!UnhookWinEvent                                                                             75EDC06F 5 Bytes  JMP 001603FC 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!CreateServiceW                                                                           770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!DeleteService                                                                            770FA07E 5 Bytes  JMP 00170600 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!SetServiceObjectSecurity                                                                 77136CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!ChangeServiceConfigA                                                                     77136DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!ChangeServiceConfigW                                                                     77136F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!ChangeServiceConfig2A                                                                    77137099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!ChangeServiceConfig2W                                                                    771371E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\System32\hkcmd.exe[2356] ADVAPI32.dll!CreateServiceA                                                                           771372A1 5 Bytes  JMP 001701F8 
.text           C:\Windows\System32\igfxpers.exe[2368] ntdll.dll!LdrLoadDll                                                                               772F9378 5 Bytes  JMP 001401F8 
.text           C:\Windows\System32\igfxpers.exe[2368] ntdll.dll!LdrUnloadDll                                                                             7730B680 5 Bytes  JMP 001403FC 
.text           C:\Windows\System32\igfxpers.exe[2368] kernel32.dll!GetBinaryTypeW + 70                                                                   76242247 1 Byte  [62]
.text           C:\Windows\System32\igfxpers.exe[2368] USER32.dll!SetWindowsHookExA                                                                       75ED6322 5 Bytes  JMP 00160600 
.text           C:\Windows\System32\igfxpers.exe[2368] USER32.dll!SetWindowsHookExW                                                                       75ED87AD 5 Bytes  JMP 00160804 
.text           C:\Windows\System32\igfxpers.exe[2368] USER32.dll!UnhookWindowsHookEx                                                                     75ED98DB 5 Bytes  JMP 00160A08 
.text           C:\Windows\System32\igfxpers.exe[2368] USER32.dll!SetWinEventHook                                                                         75ED9F3A 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\igfxpers.exe[2368] USER32.dll!UnhookWinEvent                                                                          75EDC06F 5 Bytes  JMP 001603FC 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!CreateServiceW                                                                        770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!DeleteService                                                                         770FA07E 5 Bytes  JMP 00170600 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!SetServiceObjectSecurity                                                              77136CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!ChangeServiceConfigA                                                                  77136DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!ChangeServiceConfigW                                                                  77136F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!ChangeServiceConfig2A                                                                 77137099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!ChangeServiceConfig2W                                                                 771371E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\System32\igfxpers.exe[2368] ADVAPI32.dll!CreateServiceA                                                                        771372A1 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ntdll.dll!LdrLoadDll                                       772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ntdll.dll!LdrUnloadDll                                     7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] kernel32.dll!GetBinaryTypeW + 70                           76242247 1 Byte  [62]
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] USER32.dll!SetWindowsHookExA                               75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] USER32.dll!SetWindowsHookExW                               75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] USER32.dll!UnhookWindowsHookEx                             75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] USER32.dll!SetWinEventHook                                 75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] USER32.dll!UnhookWinEvent                                  75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!CreateServiceW                                770F9EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!DeleteService                                 770FA07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!SetServiceObjectSecurity                      77136CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!ChangeServiceConfigA                          77136DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!ChangeServiceConfigW                          77136F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!ChangeServiceConfig2A                         77137099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!ChangeServiceConfig2W                         771371E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[2380] ADVAPI32.dll!CreateServiceA                                771372A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ntdll.dll!LdrLoadDll                                                            772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ntdll.dll!LdrUnloadDll                                                          7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] kernel32.dll!GetBinaryTypeW + 70                                                76242247 1 Byte  [62]
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] USER32.dll!SetWindowsHookExA                                                    75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] USER32.dll!SetWindowsHookExW                                                    75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] USER32.dll!UnhookWindowsHookEx                                                  75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] USER32.dll!SetWinEventHook                                                      75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] USER32.dll!UnhookWinEvent                                                       75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!CreateServiceW                                                     770F9EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!DeleteService                                                      770FA07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!SetServiceObjectSecurity                                           77136CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!ChangeServiceConfigA                                               77136DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!ChangeServiceConfigW                                               77136F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!ChangeServiceConfig2A                                              77137099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!ChangeServiceConfig2W                                              771371E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] ADVAPI32.dll!CreateServiceA                                                     771372A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ntdll.dll!LdrLoadDll                                                     772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ntdll.dll!LdrUnloadDll                                                   7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] kernel32.dll!GetBinaryTypeW + 70                                         76242247 1 Byte  [62]
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] USER32.dll!SetWindowsHookExA                                             75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] USER32.dll!SetWindowsHookExW                                             75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] USER32.dll!UnhookWindowsHookEx                                           75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] USER32.dll!SetWinEventHook                                               75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] USER32.dll!UnhookWinEvent                                                75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!CreateServiceW                                              770F9EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!DeleteService                                               770FA07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!SetServiceObjectSecurity                                    77136CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!ChangeServiceConfigA                                        77136DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!ChangeServiceConfigW                                        77136F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!ChangeServiceConfig2A                                       77137099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!ChangeServiceConfig2W                                       771371E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[2408] ADVAPI32.dll!CreateServiceA                                              771372A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ntdll.dll!LdrLoadDll                                                                772F9378 5 Bytes  JMP 001401F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ntdll.dll!LdrUnloadDll                                                              7730B680 5 Bytes  JMP 001403FC 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] kernel32.dll!GetBinaryTypeW + 70                                                    76242247 1 Byte  [62]
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!CreateServiceW                                                         770F9EB4 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!DeleteService                                                          770FA07E 5 Bytes  JMP 00160600 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!SetServiceObjectSecurity                                               77136CD9 5 Bytes  JMP 00161014 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!ChangeServiceConfigA                                                   77136DD9 5 Bytes  JMP 00160804 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!ChangeServiceConfigW                                                   77136F81 5 Bytes  JMP 00160A08 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!ChangeServiceConfig2A                                                  77137099 5 Bytes  JMP 00160C0C 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!ChangeServiceConfig2W                                                  771371E1 5 Bytes  JMP 00160E10 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] ADVAPI32.dll!CreateServiceA                                                         771372A1 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] USER32.dll!SetWindowsHookExA                                                        75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] USER32.dll!SetWindowsHookExW                                                        75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] USER32.dll!UnhookWindowsHookEx                                                      75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] USER32.dll!SetWinEventHook                                                          75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Unlocker\UnlockerAssistant.exe[2416] USER32.dll!UnhookWinEvent                                                           75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ntdll.dll!LdrLoadDll                                                                         772F9378 5 Bytes  JMP 001401F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ntdll.dll!LdrUnloadDll                                                                       7730B680 5 Bytes  JMP 001403FC 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] kernel32.dll!GetBinaryTypeW + 70                                                             76242247 1 Byte  [62]
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!CreateServiceW                                                                  770F9EB4 5 Bytes  JMP 001603FC 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!DeleteService                                                                   770FA07E 5 Bytes  JMP 00160600 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!SetServiceObjectSecurity                                                        77136CD9 5 Bytes  JMP 00161014 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!ChangeServiceConfigA                                                            77136DD9 5 Bytes  JMP 00160804 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!ChangeServiceConfigW                                                            77136F81 5 Bytes  JMP 00160A08 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!ChangeServiceConfig2A                                                           77137099 5 Bytes  JMP 00160C0C 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!ChangeServiceConfig2W                                                           771371E1 5 Bytes  JMP 00160E10 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] ADVAPI32.dll!CreateServiceA                                                                  771372A1 5 Bytes  JMP 001601F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] USER32.dll!SetWindowsHookExA                                                                 75ED6322 5 Bytes  JMP 00170600 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] USER32.dll!SetWindowsHookExW                                                                 75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] USER32.dll!UnhookWindowsHookEx                                                               75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] USER32.dll!SetWinEventHook                                                                   75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Windows\Samsung\PanelMgr\SSMMgr.exe[2440] USER32.dll!UnhookWinEvent                                                                    75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Winamp\winampa.exe[2604] ntdll.dll!LdrLoadDll                                                                            772F9378 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Winamp\winampa.exe[2604] ntdll.dll!LdrUnloadDll                                                                          7730B680 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Winamp\winampa.exe[2604] kernel32.dll!GetBinaryTypeW + 70                                                                76242247 1 Byte  [62]
.text           C:\Program Files\Winamp\winampa.exe[2604] USER32.dll!SetWindowsHookExA                                                                    75ED6322 5 Bytes  JMP 000A0600 
.text           C:\Program Files\Winamp\winampa.exe[2604] USER32.dll!SetWindowsHookExW                                                                    75ED87AD 5 Bytes  JMP 000A0804 
.text           C:\Program Files\Winamp\winampa.exe[2604] USER32.dll!UnhookWindowsHookEx                                                                  75ED98DB 5 Bytes  JMP 000A0A08 
.text           C:\Program Files\Winamp\winampa.exe[2604] USER32.dll!SetWinEventHook                                                                      75ED9F3A 5 Bytes  JMP 000A01F8 
.text           C:\Program Files\Winamp\winampa.exe[2604] USER32.dll!UnhookWinEvent                                                                       75EDC06F 5 Bytes  JMP 000A03FC 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!CreateServiceW                                                                     770F9EB4 5 Bytes  JMP 000B03FC 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!DeleteService                                                                      770FA07E 5 Bytes  JMP 000B0600 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!SetServiceObjectSecurity                                                           77136CD9 5 Bytes  JMP 000B1014 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!ChangeServiceConfigA                                                               77136DD9 5 Bytes  JMP 000B0804 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!ChangeServiceConfigW                                                               77136F81 5 Bytes  JMP 000B0A08 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!ChangeServiceConfig2A                                                              77137099 5 Bytes  JMP 000B0C0C 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!ChangeServiceConfig2W                                                              771371E1 5 Bytes  JMP 000B0E10 
.text           C:\Program Files\Winamp\winampa.exe[2604] ADVAPI32.dll!CreateServiceA                                                                     771372A1 5 Bytes  JMP 000B01F8 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ntdll.dll!LdrLoadDll                                                         772F9378 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ntdll.dll!LdrUnloadDll                                                       7730B680 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] kernel32.dll!GetBinaryTypeW + 70                                             76242247 1 Byte  [62]
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] USER32.dll!SetWindowsHookExA                                                 75ED6322 5 Bytes  JMP 00070600 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] USER32.dll!SetWindowsHookExW                                                 75ED87AD 5 Bytes  JMP 00070804 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] USER32.dll!UnhookWindowsHookEx                                               75ED98DB 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] USER32.dll!SetWinEventHook                                                   75ED9F3A 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] USER32.dll!UnhookWinEvent                                                    75EDC06F 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!CreateServiceW                                                  770F9EB4 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!DeleteService                                                   770FA07E 5 Bytes  JMP 00080600 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!SetServiceObjectSecurity                                        77136CD9 5 Bytes  JMP 00081014 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!ChangeServiceConfigA                                            77136DD9 5 Bytes  JMP 00080804 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!ChangeServiceConfigW                                            77136F81 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!ChangeServiceConfig2A                                           77137099 5 Bytes  JMP 00080C0C 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!ChangeServiceConfig2W                                           771371E1 5 Bytes  JMP 00080E10 
.text           C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2612] ADVAPI32.dll!CreateServiceA                                                  771372A1 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ntdll.dll!LdrLoadDll                                                                772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ntdll.dll!LdrUnloadDll                                                              7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] kernel32.dll!GetBinaryTypeW + 70                                                    76242247 1 Byte  [62]
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] USER32.dll!SetWindowsHookExA                                                        75ED6322 5 Bytes  JMP 00170600 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] USER32.dll!SetWindowsHookExW                                                        75ED87AD 5 Bytes  JMP 00170804 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] USER32.dll!UnhookWindowsHookEx                                                      75ED98DB 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] USER32.dll!SetWinEventHook                                                          75ED9F3A 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] USER32.dll!UnhookWinEvent                                                           75EDC06F 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!CreateServiceW                                                         770F9EB4 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!DeleteService                                                          770FA07E 5 Bytes  JMP 00180600 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!SetServiceObjectSecurity                                               77136CD9 5 Bytes  JMP 00181014 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!ChangeServiceConfigA                                                   77136DD9 5 Bytes  JMP 00180804 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!ChangeServiceConfigW                                                   77136F81 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!ChangeServiceConfig2A                                                  77137099 5 Bytes  JMP 00180C0C 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!ChangeServiceConfig2W                                                  771371E1 5 Bytes  JMP 00180E10 
.text           C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2700] ADVAPI32.dll!CreateServiceA                                                         771372A1 5 Bytes  JMP 001801F8 
.text           C:\Windows\System32\rundll32.exe[2740] ntdll.dll!LdrLoadDll                                                                               772F9378 5 Bytes  JMP 000601F8 
.text           C:\Windows\System32\rundll32.exe[2740] ntdll.dll!LdrUnloadDll                                                                             7730B680 5 Bytes  JMP 000603FC 
.text           C:\Windows\System32\rundll32.exe[2740] kernel32.dll!GetBinaryTypeW + 70                                                                   76242247 1 Byte  [62]
.text           C:\Windows\System32\rundll32.exe[2740] USER32.dll!SetWindowsHookExA                                                                       75ED6322 5 Bytes  JMP 00070600 
.text           C:\Windows\System32\rundll32.exe[2740] USER32.dll!SetWindowsHookExW                                                                       75ED87AD 5 Bytes  JMP 00070804 
.text           C:\Windows\System32\rundll32.exe[2740] USER32.dll!UnhookWindowsHookEx                                                                     75ED98DB 5 Bytes  JMP 00070A08 
.text           C:\Windows\System32\rundll32.exe[2740] USER32.dll!SetWinEventHook                                                                         75ED9F3A 5 Bytes  JMP 000701F8 
.text           C:\Windows\System32\rundll32.exe[2740] USER32.dll!UnhookWinEvent                                                                          75EDC06F 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!CreateServiceW                                                                        770F9EB4 5 Bytes  JMP 000803FC 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!DeleteService                                                                         770FA07E 5 Bytes  JMP 00080600 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!SetServiceObjectSecurity                                                              77136CD9 5 Bytes  JMP 00081014 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!ChangeServiceConfigA                                                                  77136DD9 5 Bytes  JMP 00080804 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!ChangeServiceConfigW                                                                  77136F81 5 Bytes  JMP 00080A08 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!ChangeServiceConfig2A                                                                 77137099 5 Bytes  JMP 00080C0C 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!ChangeServiceConfig2W                                                                 771371E1 5 Bytes  JMP 00080E10 
.text           C:\Windows\System32\rundll32.exe[2740] ADVAPI32.dll!CreateServiceA                                                                        771372A1 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Alwil Software\Avast5\AvastUI.exe[2840] kernel32.dll!GetBinaryTypeW + 70                                                 76242247 1 Byte  [62]
.text           C:\Windows\system32\agrsmsvc.exe[2860] ntdll.dll!LdrLoadDll                                                                               772F9378 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ntdll.dll!LdrUnloadDll                                                                             7730B680 5 Bytes  JMP 000803FC 
.text           C:\Windows\system32\agrsmsvc.exe[2860] kernel32.dll!GetBinaryTypeW + 70                                                                   76242247 1 Byte  [62]
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!CreateServiceW                                                                        770F9EB4 5 Bytes  JMP 000A03FC 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!DeleteService                                                                         770FA07E 5 Bytes  JMP 000A0600 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!SetServiceObjectSecurity                                                              77136CD9 5 Bytes  JMP 000A1014 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!ChangeServiceConfigA                                                                  77136DD9 5 Bytes  JMP 000A0804 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!ChangeServiceConfigW                                                                  77136F81 5 Bytes  JMP 000A0A08 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!ChangeServiceConfig2A                                                                 77137099 5 Bytes  JMP 000A0C0C 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!ChangeServiceConfig2W                                                                 771371E1 5 Bytes  JMP 000A0E10 
.text           C:\Windows\system32\agrsmsvc.exe[2860] ADVAPI32.dll!CreateServiceA                                                                        771372A1 5 Bytes  JMP 000A01F8 
.text           C:\Windows\system32\agrsmsvc.exe[2860] USER32.dll!SetWindowsHookExA                                                                       75ED6322 5 Bytes  JMP 000B0600 
.text           C:\Windows\system32\agrsmsvc.exe[2860] USER32.dll!SetWindowsHookExW                                                                       75ED87AD 5 Bytes  JMP 000B0804 
.text           C:\Windows\system32\agrsmsvc.exe[2860] USER32.dll!UnhookWindowsHookEx                                                                     75ED98DB 5 Bytes  JMP 000B0A08 
.text           C:\Windows\system32\agrsmsvc.exe[2860] USER32.dll!SetWinEventHook                                                                         75ED9F3A 5 Bytes  JMP 000B01F8 
.text           C:\Windows\system32\agrsmsvc.exe[2860] USER32.dll!UnhookWinEvent                                                                          75EDC06F 5 Bytes  JMP 000B03FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ntdll.dll!LdrLoadDll                                                                 772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ntdll.dll!LdrUnloadDll                                                               7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] kernel32.dll!GetBinaryTypeW + 70                                                     76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] USER32.dll!SetWindowsHookExA                                                         75ED6322 5 Bytes  JMP 002D0600 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] USER32.dll!SetWindowsHookExW                                                         75ED87AD 5 Bytes  JMP 002D0804 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] USER32.dll!UnhookWindowsHookEx                                                       75ED98DB 5 Bytes  JMP 002D0A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] USER32.dll!SetWinEventHook                                                           75ED9F3A 5 Bytes  JMP 002D01F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] USER32.dll!UnhookWinEvent                                                            75EDC06F 5 Bytes  JMP 002D03FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!CreateServiceW                                                          770F9EB4 5 Bytes  JMP 002E03FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!DeleteService                                                           770FA07E 5 Bytes  JMP 002E0600 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!SetServiceObjectSecurity                                                77136CD9 5 Bytes  JMP 002E1014 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!ChangeServiceConfigA                                                    77136DD9 5 Bytes  JMP 002E0804 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!ChangeServiceConfigW                                                    77136F81 5 Bytes  JMP 002E0A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!ChangeServiceConfig2A                                                   77137099 5 Bytes  JMP 002E0C0C 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!ChangeServiceConfig2W                                                   771371E1 5 Bytes  JMP 002E0E10 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[2928] ADVAPI32.dll!CreateServiceA                                                          771372A1 5 Bytes  JMP 002E01F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ntdll.dll!LdrLoadDll                                                                772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ntdll.dll!LdrUnloadDll                                                              7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] kernel32.dll!GetBinaryTypeW + 70                                                    76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] USER32.dll!SetWindowsHookExA                                                        75ED6322 5 Bytes  JMP 00220600 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] USER32.dll!SetWindowsHookExW                                                        75ED87AD 5 Bytes  JMP 00220804 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] USER32.dll!UnhookWindowsHookEx                                                      75ED98DB 5 Bytes  JMP 00220A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] USER32.dll!SetWinEventHook                                                          75ED9F3A 5 Bytes  JMP 002201F8 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] USER32.dll!UnhookWinEvent                                                           75EDC06F 5 Bytes  JMP 002203FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!CreateServiceW                                                         770F9EB4 5 Bytes  JMP 002303FC 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!DeleteService                                                          770FA07E 5 Bytes  JMP 00230600 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!SetServiceObjectSecurity                                               77136CD9 5 Bytes  JMP 00231014 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!ChangeServiceConfigA                                                   77136DD9 5 Bytes  JMP 00230804 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!ChangeServiceConfigW                                                   77136F81 5 Bytes  JMP 00230A08 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!ChangeServiceConfig2A                                                  77137099 5 Bytes  JMP 00230C0C 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!ChangeServiceConfig2W                                                  771371E1 5 Bytes  JMP 00230E10 
.text           C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] ADVAPI32.dll!CreateServiceA                                                         771372A1 5 Bytes  JMP 002301F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ntdll.dll!LdrLoadDll                                                     772F9378 5 Bytes  JMP 001601F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ntdll.dll!LdrUnloadDll                                                   7730B680 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] kernel32.dll!GetBinaryTypeW + 70                                         76242247 1 Byte  [62]
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!CreateServiceW                                              770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!DeleteService                                               770FA07E 5 Bytes  JMP 00170600 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!SetServiceObjectSecurity                                    77136CD9 5 Bytes  JMP 00171014 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!ChangeServiceConfigA                                        77136DD9 5 Bytes  JMP 00170804 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!ChangeServiceConfigW                                        77136F81 5 Bytes  JMP 00170A08 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!ChangeServiceConfig2A                                       77137099 5 Bytes  JMP 00170C0C 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!ChangeServiceConfig2W                                       771371E1 5 Bytes  JMP 00170E10 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] ADVAPI32.dll!CreateServiceA                                              771372A1 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] USER32.dll!SetWindowsHookExA                                             75ED6322 5 Bytes  JMP 00180600 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] USER32.dll!SetWindowsHookExW                                             75ED87AD 5 Bytes  JMP 00180804 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] USER32.dll!UnhookWindowsHookEx                                           75ED98DB 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] USER32.dll!SetWinEventHook                                               75ED9F3A 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Common Files\Java\Java Update\jusched.exe[3068] USER32.dll!UnhookWinEvent                                                75EDC06F 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ntdll.dll!LdrLoadDll                                                                   772F9378 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ntdll.dll!LdrUnloadDll                                                                 7730B680 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] kernel32.dll!GetBinaryTypeW + 70                                                       76242247 1 Byte  [62]
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!CreateServiceW                                                            770F9EB4 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!DeleteService                                                             770FA07E 5 Bytes  JMP 00080600 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!SetServiceObjectSecurity                                                  77136CD9 5 Bytes  JMP 00081014 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!ChangeServiceConfigA                                                      77136DD9 5 Bytes  JMP 00080804 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!ChangeServiceConfigW                                                      77136F81 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!ChangeServiceConfig2A                                                     77137099 5 Bytes  JMP 00080C0C 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!ChangeServiceConfig2W                                                     771371E1 5 Bytes  JMP 00080E10 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] ADVAPI32.dll!CreateServiceA                                                            771372A1 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] USER32.dll!SetWindowsHookExA                                                           75ED6322 5 Bytes  JMP 00090600 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] USER32.dll!SetWindowsHookExW                                                           75ED87AD 5 Bytes  JMP 00090804 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] USER32.dll!UnhookWindowsHookEx                                                         75ED98DB 5 Bytes  JMP 00090A08 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] USER32.dll!SetWinEventHook                                                             75ED9F3A 5 Bytes  JMP 000901F8 
.text           C:\Program Files\Windows Sidebar\sidebar.exe[3076] USER32.dll!UnhookWinEvent                                                              75EDC06F 5 Bytes  JMP 000903FC 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ntdll.dll!LdrLoadDll                                                                 772F9378 5 Bytes  JMP 001401F8 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ntdll.dll!LdrUnloadDll                                                               7730B680 5 Bytes  JMP 001403FC 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] kernel32.dll!GetBinaryTypeW + 70                                                     76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] USER32.dll!SetWindowsHookExA                                                         75ED6322 5 Bytes  JMP 00160600 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] USER32.dll!SetWindowsHookExW                                                         75ED87AD 5 Bytes  JMP 00160804 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] USER32.dll!UnhookWindowsHookEx                                                       75ED98DB 5 Bytes  JMP 00160A08 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] USER32.dll!SetWinEventHook                                                           75ED9F3A 5 Bytes  JMP 001601F8 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] USER32.dll!UnhookWinEvent                                                            75EDC06F 5 Bytes  JMP 001603FC 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!CreateServiceW                                                          770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!DeleteService                                                           770FA07E 5 Bytes  JMP 00170600 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!SetServiceObjectSecurity                                                77136CD9 5 Bytes  JMP 00171014 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!ChangeServiceConfigA                                                    77136DD9 5 Bytes  JMP 00170804 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!ChangeServiceConfigW                                                    77136F81 5 Bytes  JMP 00170A08 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!ChangeServiceConfig2A                                                   77137099 5 Bytes  JMP 00170C0C 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!ChangeServiceConfig2W                                                   771371E1 5 Bytes  JMP 00170E10 
.text           C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3120] ADVAPI32.dll!CreateServiceA                                                          771372A1 5 Bytes  JMP 001701F8 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ntdll.dll!LdrLoadDll                                                             772F9378 5 Bytes  JMP 000501F8 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ntdll.dll!LdrUnloadDll                                                           7730B680 5 Bytes  JMP 000503FC 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] kernel32.dll!GetBinaryTypeW + 70                                                 76242247 1 Byte  [62]
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!CreateServiceW                                                      770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!DeleteService                                                       770FA07E 5 Bytes  JMP 00070600 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!SetServiceObjectSecurity                                            77136CD9 5 Bytes  JMP 00071014 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!ChangeServiceConfigA                                                77136DD9 5 Bytes  JMP 00070804 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!ChangeServiceConfigW                                                77136F81 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!ChangeServiceConfig2A                                               77137099 5 Bytes  JMP 00070C0C 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!ChangeServiceConfig2W                                               771371E1 5 Bytes  JMP 00070E10 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] ADVAPI32.dll!CreateServiceA                                                      771372A1 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] USER32.dll!SetWindowsHookExA                                                     75ED6322 5 Bytes  JMP 00080600 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] USER32.dll!SetWindowsHookExW                                                     75ED87AD 5 Bytes  JMP 00080804 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] USER32.dll!UnhookWindowsHookEx                                                   75ED98DB 5 Bytes  JMP 00080A08 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] USER32.dll!SetWinEventHook                                                       75ED9F3A 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Windows Media Player\wmpnscfg.exe[3136] USER32.dll!UnhookWinEvent                                                        75EDC06F 5 Bytes  JMP 000803FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ntdll.dll!LdrLoadDll                                                  772F9378 5 Bytes  JMP 001401F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ntdll.dll!LdrUnloadDll                                                7730B680 5 Bytes  JMP 001403FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] kernel32.dll!GetBinaryTypeW + 70                                      76242247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] USER32.dll!SetWindowsHookExA                                          75ED6322 5 Bytes  JMP 00170600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] USER32.dll!SetWindowsHookExW                                          75ED87AD 5 Bytes  JMP 00170804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] USER32.dll!UnhookWindowsHookEx                                        75ED98DB 5 Bytes  JMP 00170A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] USER32.dll!SetWinEventHook                                            75ED9F3A 5 Bytes  JMP 001701F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] USER32.dll!UnhookWinEvent                                             75EDC06F 5 Bytes  JMP 001703FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!CreateServiceW                                           770F9EB4 5 Bytes  JMP 001803FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!DeleteService                                            770FA07E 5 Bytes  JMP 00180600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!SetServiceObjectSecurity                                 77136CD9 5 Bytes  JMP 00181014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!ChangeServiceConfigA                                     77136DD9 5 Bytes  JMP 00180804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!ChangeServiceConfigW                                     77136F81 5 Bytes  JMP 00180A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!ChangeServiceConfig2A                                    77137099 5 Bytes  JMP 00180C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!ChangeServiceConfig2W                                    771371E1 5 Bytes  JMP 00180E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] ADVAPI32.dll!CreateServiceA                                           771372A1 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ntdll.dll!LdrLoadDll                                                  772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ntdll.dll!LdrUnloadDll                                                7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] kernel32.dll!GetBinaryTypeW + 70                                      76242247 1 Byte  [62]
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] USER32.dll!SetWindowsHookExA                                          75ED6322 5 Bytes  JMP 00E20600 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] USER32.dll!SetWindowsHookExW                                          75ED87AD 5 Bytes  JMP 00E20804 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] USER32.dll!UnhookWindowsHookEx                                        75ED98DB 5 Bytes  JMP 00E20A08 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] USER32.dll!SetWinEventHook                                            75ED9F3A 5 Bytes  JMP 00E201F8 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] USER32.dll!UnhookWinEvent                                             75EDC06F 5 Bytes  JMP 00E203FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!CreateServiceW                                           770F9EB4 5 Bytes  JMP 00E303FC 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!DeleteService                                            770FA07E 5 Bytes  JMP 00E30600 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!SetServiceObjectSecurity                                 77136CD9 5 Bytes  JMP 00E31014 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!ChangeServiceConfigA                                     77136DD9 5 Bytes  JMP 00E30804 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!ChangeServiceConfigW                                     77136F81 5 Bytes  JMP 00E30A08 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!ChangeServiceConfig2A                                    77137099 5 Bytes  JMP 00E30C0C 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!ChangeServiceConfig2W                                    771371E1 5 Bytes  JMP 00E30E10 
.text           C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3240] ADVAPI32.dll!CreateServiceA                                           771372A1 5 Bytes  JMP 00E301F8 
.text           C:\Windows\system32\svchost.exe[3448] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[3448] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[3448] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[3448] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\svchost.exe[3448] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 000F0600 
.text           C:\Windows\system32\svchost.exe[3448] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 000F0804 
.text           C:\Windows\system32\svchost.exe[3448] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 000F0A08 
.text           C:\Windows\system32\svchost.exe[3448] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 000F01F8 
.text           C:\Windows\system32\svchost.exe[3448] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 000F03FC 
.text           C:\Windows\system32\svchost.exe[3476] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[3476] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[3476] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[3476] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\TODDSrv.exe[3548] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 001401F8 
.text           C:\Windows\system32\TODDSrv.exe[3548] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 001403FC 
.text           C:\Windows\system32\TODDSrv.exe[3548] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\TODDSrv.exe[3548] USER32.dll!SetWindowsHookExA                                                                        75ED6322 5 Bytes  JMP 00160600 
.text           C:\Windows\system32\TODDSrv.exe[3548] USER32.dll!SetWindowsHookExW                                                                        75ED87AD 5 Bytes  JMP 00160804 
.text           C:\Windows\system32\TODDSrv.exe[3548] USER32.dll!UnhookWindowsHookEx                                                                      75ED98DB 5 Bytes  JMP 00160A08 
.text           C:\Windows\system32\TODDSrv.exe[3548] USER32.dll!SetWinEventHook                                                                          75ED9F3A 5 Bytes  JMP 001601F8 
.text           C:\Windows\system32\TODDSrv.exe[3548] USER32.dll!UnhookWinEvent                                                                           75EDC06F 5 Bytes  JMP 001603FC 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 001703FC 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00170600 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00171014 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00170804 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00170A08 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00170C0C 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00170E10 
.text           C:\Windows\system32\TODDSrv.exe[3548] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 001701F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ntdll.dll!LdrLoadDll                                                              772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ntdll.dll!LdrUnloadDll                                                            7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] kernel32.dll!GetBinaryTypeW + 70                                                  76242247 1 Byte  [62]
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!CreateServiceW                                                       770F9EB4 5 Bytes  JMP 001A03FC 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!DeleteService                                                        770FA07E 5 Bytes  JMP 001A0600 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!SetServiceObjectSecurity                                             77136CD9 5 Bytes  JMP 001A1014 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!ChangeServiceConfigA                                                 77136DD9 5 Bytes  JMP 001A0804 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!ChangeServiceConfigW                                                 77136F81 5 Bytes  JMP 001A0A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!ChangeServiceConfig2A                                                77137099 5 Bytes  JMP 001A0C0C 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!ChangeServiceConfig2W                                                771371E1 5 Bytes  JMP 001A0E10 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] ADVAPI32.dll!CreateServiceA                                                       771372A1 5 Bytes  JMP 001A01F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] USER32.dll!SetWindowsHookExA                                                      75ED6322 5 Bytes  JMP 001B0600 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] USER32.dll!SetWindowsHookExW                                                      75ED87AD 5 Bytes  JMP 001B0804 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] USER32.dll!UnhookWindowsHookEx                                                    75ED98DB 5 Bytes  JMP 001B0A08 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] USER32.dll!SetWinEventHook                                                        75ED9F3A 5 Bytes  JMP 001B01F8 
.text           C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[3636] USER32.dll!UnhookWinEvent                                                         75EDC06F 5 Bytes  JMP 001B03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ntdll.dll!LdrLoadDll                                                  772F9378 5 Bytes  JMP 001401F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ntdll.dll!LdrUnloadDll                                                7730B680 5 Bytes  JMP 001403FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] kernel32.dll!GetBinaryTypeW + 70                                      76242247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!CreateServiceW                                           770F9EB4 5 Bytes  JMP 001703FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!DeleteService                                            770FA07E 5 Bytes  JMP 00170600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!SetServiceObjectSecurity                                 77136CD9 5 Bytes  JMP 00171014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!ChangeServiceConfigA                                     77136DD9 5 Bytes  JMP 00170804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!ChangeServiceConfigW                                     77136F81 5 Bytes  JMP 00170A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!ChangeServiceConfig2A                                    77137099 5 Bytes  JMP 00170C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!ChangeServiceConfig2W                                    771371E1 5 Bytes  JMP 00170E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] ADVAPI32.dll!CreateServiceA                                           771372A1 5 Bytes  JMP 001701F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] USER32.dll!SetWindowsHookExA                                          75ED6322 5 Bytes  JMP 00180600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] USER32.dll!SetWindowsHookExW                                          75ED87AD 5 Bytes  JMP 00180804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] USER32.dll!UnhookWindowsHookEx                                        75ED98DB 5 Bytes  JMP 00180A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] USER32.dll!SetWinEventHook                                            75ED9F3A 5 Bytes  JMP 001801F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe[3712] USER32.dll!UnhookWinEvent                                             75EDC06F 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ntdll.dll!LdrLoadDll                                                   772F9378 5 Bytes  JMP 001401F8 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ntdll.dll!LdrUnloadDll                                                 7730B680 5 Bytes  JMP 001403FC 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] kernel32.dll!GetBinaryTypeW + 70                                       76242247 1 Byte  [62]
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!CreateServiceW                                            770F9EB4 5 Bytes  JMP 001603FC 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!DeleteService                                             770FA07E 5 Bytes  JMP 00160600 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!SetServiceObjectSecurity                                  77136CD9 5 Bytes  JMP 00161014 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!ChangeServiceConfigA                                      77136DD9 5 Bytes  JMP 00160804 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!ChangeServiceConfigW                                      77136F81 5 Bytes  JMP 00160A08 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!ChangeServiceConfig2A                                     77137099 5 Bytes  JMP 00160C0C 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!ChangeServiceConfig2W                                     771371E1 5 Bytes  JMP 00160E10 
.text           C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3740] ADVAPI32.dll!CreateServiceA                                            771372A1 5 Bytes  JMP 001601F8 
.text           C:\Windows\System32\svchost.exe[3760] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\System32\svchost.exe[3760] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\System32\svchost.exe[3760] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\System32\svchost.exe[3760] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ntdll.dll!LdrLoadDll                                                                          772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ntdll.dll!LdrUnloadDll                                                                        7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\SearchIndexer.exe[3792] kernel32.dll!GetBinaryTypeW + 70                                                              76242247 1 Byte  [62]
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!CreateServiceW                                                                   770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!DeleteService                                                                    770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!SetServiceObjectSecurity                                                         77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!ChangeServiceConfigA                                                             77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!ChangeServiceConfigW                                                             77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!ChangeServiceConfig2A                                                            77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!ChangeServiceConfig2W                                                            771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\SearchIndexer.exe[3792] ADVAPI32.dll!CreateServiceA                                                                   771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\system32\SearchIndexer.exe[3792] USER32.dll!SetWindowsHookExA                                                                  75ED6322 5 Bytes  JMP 00080600 
.text           C:\Windows\system32\SearchIndexer.exe[3792] USER32.dll!SetWindowsHookExW                                                                  75ED87AD 5 Bytes  JMP 00080804 
.text           C:\Windows\system32\SearchIndexer.exe[3792] USER32.dll!UnhookWindowsHookEx                                                                75ED98DB 5 Bytes  JMP 00080A08 
.text           C:\Windows\system32\SearchIndexer.exe[3792] USER32.dll!SetWinEventHook                                                                    75ED9F3A 5 Bytes  JMP 000801F8 
.text           C:\Windows\system32\SearchIndexer.exe[3792] USER32.dll!UnhookWinEvent                                                                     75EDC06F 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ntdll.dll!LdrLoadDll                                                             772F9378 5 Bytes  JMP 000401F8 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ntdll.dll!LdrUnloadDll                                                           7730B680 5 Bytes  JMP 000403FC 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] kernel32.dll!GetBinaryTypeW + 70                                                 76242247 1 Byte  [62]
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!CreateServiceW                                                      770F9EB4 5 Bytes  JMP 000603FC 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!DeleteService                                                       770FA07E 5 Bytes  JMP 00060600 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!SetServiceObjectSecurity                                            77136CD9 5 Bytes  JMP 00061014 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!ChangeServiceConfigA                                                77136DD9 5 Bytes  JMP 00060804 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!ChangeServiceConfigW                                                77136F81 5 Bytes  JMP 00060A08 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!ChangeServiceConfig2A                                               77137099 5 Bytes  JMP 00060C0C 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!ChangeServiceConfig2W                                               771371E1 5 Bytes  JMP 00060E10 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] ADVAPI32.dll!CreateServiceA                                                      771372A1 5 Bytes  JMP 000601F8 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] USER32.dll!SetWindowsHookExA                                                     75ED6322 5 Bytes  JMP 00070600 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] USER32.dll!SetWindowsHookExW                                                     75ED87AD 5 Bytes  JMP 00070804 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] USER32.dll!UnhookWindowsHookEx                                                   75ED98DB 5 Bytes  JMP 00070A08 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] USER32.dll!SetWinEventHook                                                       75ED9F3A 5 Bytes  JMP 000701F8 
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[4084] USER32.dll!UnhookWinEvent                                                        75EDC06F 5 Bytes  JMP 000703FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ntdll.dll!LdrLoadDll                                                  772F9378 5 Bytes  JMP 001501F8 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ntdll.dll!LdrUnloadDll                                                7730B680 5 Bytes  JMP 001503FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] kernel32.dll!GetBinaryTypeW + 70                                      76242247 1 Byte  [62]
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] USER32.dll!SetWindowsHookExA                                          75ED6322 5 Bytes  JMP 00180600 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] USER32.dll!SetWindowsHookExW                                          75ED87AD 5 Bytes  JMP 00180804 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] USER32.dll!UnhookWindowsHookEx                                        75ED98DB 5 Bytes  JMP 00180A08 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] USER32.dll!SetWinEventHook                                            75ED9F3A 5 Bytes  JMP 001801F8 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] USER32.dll!UnhookWinEvent                                             75EDC06F 5 Bytes  JMP 001803FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!CreateServiceW                                           770F9EB4 5 Bytes  JMP 001903FC 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!DeleteService                                            770FA07E 5 Bytes  JMP 00190600 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!SetServiceObjectSecurity                                 77136CD9 5 Bytes  JMP 00191014 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!ChangeServiceConfigA                                     77136DD9 5 Bytes  JMP 00190804 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!ChangeServiceConfigW                                     77136F81 5 Bytes  JMP 00190A08 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!ChangeServiceConfig2A                                    77137099 5 Bytes  JMP 00190C0C 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!ChangeServiceConfig2W                                    771371E1 5 Bytes  JMP 00190E10 
.text           C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] ADVAPI32.dll!CreateServiceA                                           771372A1 5 Bytes  JMP 001901F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ntdll.dll!LdrLoadDll                                                  772F9378 5 Bytes  JMP 001401F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ntdll.dll!LdrUnloadDll                                                7730B680 5 Bytes  JMP 001403FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] kernel32.dll!GetBinaryTypeW + 70                                      76242247 1 Byte  [62]
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] USER32.dll!SetWindowsHookExA                                          75ED6322 5 Bytes  JMP 003A0600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] USER32.dll!SetWindowsHookExW                                          75ED87AD 5 Bytes  JMP 003A0804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] USER32.dll!UnhookWindowsHookEx                                        75ED98DB 5 Bytes  JMP 003A0A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] USER32.dll!SetWinEventHook                                            75ED9F3A 5 Bytes  JMP 003A01F8 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] USER32.dll!UnhookWinEvent                                             75EDC06F 5 Bytes  JMP 003A03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!CreateServiceW                                           770F9EB4 5 Bytes  JMP 003B03FC 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!DeleteService                                            770FA07E 5 Bytes  JMP 003B0600 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!SetServiceObjectSecurity                                 77136CD9 5 Bytes  JMP 003B1014 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!ChangeServiceConfigA                                     77136DD9 5 Bytes  JMP 003B0804 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!ChangeServiceConfigW                                     77136F81 5 Bytes  JMP 003B0A08 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!ChangeServiceConfig2A                                    77137099 5 Bytes  JMP 003B0C0C 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!ChangeServiceConfig2W                                    771371E1 5 Bytes  JMP 003B0E10 
.text           c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] ADVAPI32.dll!CreateServiceA                                           771372A1 5 Bytes  JMP 003B01F8 
.text           C:\Windows\system32\svchost.exe[4472] ntdll.dll!LdrLoadDll                                                                                772F9378 5 Bytes  JMP 000501F8 
.text           C:\Windows\system32\svchost.exe[4472] ntdll.dll!LdrUnloadDll                                                                              7730B680 5 Bytes  JMP 000503FC 
.text           C:\Windows\system32\svchost.exe[4472] kernel32.dll!GetBinaryTypeW + 70                                                                    76242247 1 Byte  [62]
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!CreateServiceW                                                                         770F9EB4 5 Bytes  JMP 000703FC 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!DeleteService                                                                          770FA07E 5 Bytes  JMP 00070600 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!SetServiceObjectSecurity                                                               77136CD9 5 Bytes  JMP 00071014 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!ChangeServiceConfigA                                                                   77136DD9 5 Bytes  JMP 00070804 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!ChangeServiceConfigW                                                                   77136F81 5 Bytes  JMP 00070A08 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!ChangeServiceConfig2A                                                                  77137099 5 Bytes  JMP 00070C0C 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!ChangeServiceConfig2W                                                                  771371E1 5 Bytes  JMP 00070E10 
.text           C:\Windows\system32\svchost.exe[4472] ADVAPI32.dll!CreateServiceA                                                                         771372A1 5 Bytes  JMP 000701F8 
.text           C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[4600] KERNEL32.dll!GetBinaryTypeW + 70                              76242247 1 Byte  [62]
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ntdll.dll!LdrLoadDll                                                                      772F9378 5 Bytes  JMP 000401F8 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ntdll.dll!LdrUnloadDll                                                                    7730B680 5 Bytes  JMP 000403FC 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] kernel32.dll!GetBinaryTypeW + 70                                                          76242247 1 Byte  [62]
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!CreateServiceW                                                               770F9EB4 5 Bytes  JMP 000603FC 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!DeleteService                                                                770FA07E 5 Bytes  JMP 00060600 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!SetServiceObjectSecurity                                                     77136CD9 5 Bytes  JMP 00061014 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!ChangeServiceConfigA                                                         77136DD9 5 Bytes  JMP 00060804 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!ChangeServiceConfigW                                                         77136F81 5 Bytes  JMP 00060A08 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!ChangeServiceConfig2A                                                        77137099 5 Bytes  JMP 00060C0C 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!ChangeServiceConfig2W                                                        771371E1 5 Bytes  JMP 00060E10 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] ADVAPI32.dll!CreateServiceA                                                               771372A1 5 Bytes  JMP 000601F8 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] USER32.dll!SetWindowsHookExA                                                              75ED6322 5 Bytes  JMP 00070600 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] USER32.dll!SetWindowsHookExW                                                              75ED87AD 5 Bytes  JMP 00070804 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] USER32.dll!UnhookWindowsHookEx                                                            75ED98DB 5 Bytes  JMP 00070A08 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] USER32.dll!SetWinEventHook                                                                75ED9F3A 5 Bytes  JMP 000701F8 
.text           C:\Windows\servicing\TrustedInstaller.exe[4872] USER32.dll!UnhookWinEvent                                                                 75EDC06F 5 Bytes  JMP 000703FC 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ntdll.dll!LdrLoadDll                                                                        772F9378 5 Bytes  JMP 001501F8 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ntdll.dll!LdrUnloadDll                                                                      7730B680 5 Bytes  JMP 001503FC 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] kernel32.dll!GetBinaryTypeW + 70                                                            76242247 1 Byte  [62]
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!CreateServiceW                                                                 770F9EB4 5 Bytes  JMP 002703FC 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!DeleteService                                                                  770FA07E 5 Bytes  JMP 00270600 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!SetServiceObjectSecurity                                                       77136CD9 5 Bytes  JMP 00271014 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!ChangeServiceConfigA                                                           77136DD9 5 Bytes  JMP 00270804 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!ChangeServiceConfigW                                                           77136F81 5 Bytes  JMP 00270A08 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!ChangeServiceConfig2A                                                          77137099 5 Bytes  JMP 00270C0C 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!ChangeServiceConfig2W                                                          771371E1 5 Bytes  JMP 00270E10 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] ADVAPI32.dll!CreateServiceA                                                                 771372A1 5 Bytes  JMP 002701F8 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] USER32.dll!SetWindowsHookExA                                                                75ED6322 5 Bytes  JMP 00020600 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] USER32.dll!SetWindowsHookExW                                                                75ED87AD 5 Bytes  JMP 00020804 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] USER32.dll!UnhookWindowsHookEx                                                              75ED98DB 5 Bytes  JMP 00020A08 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] USER32.dll!SetWinEventHook                                                                  75ED9F3A 5 Bytes  JMP 000201F8 
.text           C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] USER32.dll!UnhookWinEvent                                                                   75EDC06F 5 Bytes  JMP 000203FC 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ntdll.dll!LdrLoadDll                                                    772F9378 5 Bytes  JMP 000401F8 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ntdll.dll!LdrUnloadDll                                                  7730B680 5 Bytes  JMP 000403FC 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] kernel32.dll!GetBinaryTypeW + 70                                        76242247 1 Byte  [62]
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!CreateServiceW                                             770F9EB4 5 Bytes  JMP 000D03FC 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!DeleteService                                              770FA07E 5 Bytes  JMP 000D0600 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!SetServiceObjectSecurity                                   77136CD9 5 Bytes  JMP 000D1014 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!ChangeServiceConfigA                                       77136DD9 5 Bytes  JMP 000D0804 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!ChangeServiceConfigW                                       77136F81 5 Bytes  JMP 000D0A08 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!ChangeServiceConfig2A                                      77137099 5 Bytes  JMP 000D0C0C 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!ChangeServiceConfig2W                                      771371E1 5 Bytes  JMP 000D0E10 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] ADVAPI32.dll!CreateServiceA                                             771372A1 5 Bytes  JMP 000D01F8 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] USER32.dll!SetWindowsHookExA                                            75ED6322 5 Bytes  JMP 001E0600 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] USER32.dll!SetWindowsHookExW                                            75ED87AD 5 Bytes  JMP 001E0804 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] USER32.dll!UnhookWindowsHookEx                                          75ED98DB 5 Bytes  JMP 001E0A08 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] USER32.dll!SetWinEventHook                                              75ED9F3A 5 Bytes  JMP 001E01F8 
.text           C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[6040] USER32.dll!UnhookWinEvent                                               75EDC06F 5 Bytes  JMP 001E03FC 

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Windows\system32\services.exe[636] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]                              001E0002
IAT             C:\Windows\system32\services.exe[636] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW]                                    001E0000
IAT             C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1656] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                  [72F3F6A0] C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll (Common functions/AVAST Software)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                     [74167817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                      [741BA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                  [7416BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                            [7415F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                      [741675E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                   [7415E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                       [74198395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                          [7416DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                  [7415FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                   [7415FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                    [741571CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                            [741ECAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                               [7418C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                  [7415D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                            [74156853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                           [7415687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                              [74162AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                 [03A92EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                                                      [03A92C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                        [03A92C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Windows\Explorer.EXE[2024] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                            [03A92C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]            [00E42EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                 [00E42C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]   [00E42C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe[2248] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]       [00E42C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                     [01B92EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                          [01B92C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]            [01B92C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[2396] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                [01B92C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Alwil Software\Avast5\AvastUI.exe[2840] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                   [72F3F6A0] C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll (Common functions/AVAST Software)
IAT             C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                         [01EE2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                              [01EE2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                [01EE2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe[3040] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                    [01EE2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]           [00B72EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                [00B72C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]  [00B72C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe[3164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]      [00B72C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]           [00202EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                [00202C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]  [00202C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[4244] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]      [00202C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]           [01C62EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                [01C62C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]  [01C62C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]      [01C62C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                 [002A2EC0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                                      [002A2C90] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                        [002A2C30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Instalki\Bezpieczeństwo\4ki9svdy.exe[5484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                            [002A2C60] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                                    aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                                                                   Wdf01000.sys (Dynamiczna struktura WDF/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                                                                   Wdf01000.sys (Dynamiczna struktura WDF/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                   aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                   aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

---- EOF - GMER 1.0.15 ----
